Technical Information
- %TEMP%\uac.bat
- %TEMP%\aut.bat
- %TEMP%\uac.bat
- DNS ASK aq#####osmeticos.com.br
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\uac.bat
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\aut.bat
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\uac.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\aut.bat' (with hidden window)