Technical Information
- %TEMP%\20230913t210340_625.exe
- %TEMP%\20230913t210406_165.exe
- '20##########340_625.ltiapmyzmjxrvrts.info':80
- '20##########406_165.ltiapmyzmjxrvrts.info':80
- '20##########428_075.ltiapmyzmjxrvrts.info':80
- http://20##########340_625.ltiapmyzmjxrvrts.info/v4/20230913T210340_625.exe
- http://20##########406_165.ltiapmyzmjxrvrts.info/v4/20230913T210406_165.exe
- http://20##########428_075.ltiapmyzmjxrvrts.info/v4/20230913T210428_075.exe
- DNS ASK 20##########340_625.ltiapmyzmjxrvrts.info
- DNS ASK 20##########406_165.ltiapmyzmjxrvrts.info
- DNS ASK 20##########428_075.ltiapmyzmjxrvrts.info
- '%TEMP%\20230913t210340_625.exe'
- '%TEMP%\20230913t210406_165.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T210340_625.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T210406_165.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T210428_075.exe