Technical Information
- %TEMP%\20230923t030901_044.exe
- '20##########901_044.ltiapmyzmjxrvrts.info':80
- '20##########034_078.ltiapmyzmjxrvrts.info':80
- http://20##########901_044.ltiapmyzmjxrvrts.info/v4/20230923T030901_044.exe
- http://20##########034_078.ltiapmyzmjxrvrts.info/v4/20230923T031034_078.exe
- DNS ASK 20##########901_044.ltiapmyzmjxrvrts.info
- DNS ASK 20##########034_078.ltiapmyzmjxrvrts.info
- '%TEMP%\20230923t030901_044.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230923T030901_044.exe