Technical Information
- %TEMP%\2ty9o5sforyttry9orw4tryowyro.txt
- 'wi#####.redirectme.net':80
- http://wi#####.redirectme.net/BCC/UXlzc2FueEJjV3hBZEZNdFEzUmhiMXArSkNRPQ==.php
- DNS ASK wi#####.redirectme.net
- '<SYSTEM32>\cmd.exe' /c tasklist
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\cmd.exe' /c hostname
- '<SYSTEM32>\hostname.exe'