Technical Information
- %TEMP%\20230914t030817_879.exe
- %TEMP%\20230914t030908_031.exe
- '20##########817_879.ltiapmyzmjxrvrts.info':80
- '20##########908_031.ltiapmyzmjxrvrts.info':80
- http://20##########817_879.ltiapmyzmjxrvrts.info/v4/20230914T030817_879.exe
- http://20##########908_031.ltiapmyzmjxrvrts.info/v4/20230914T030908_031.exe
- DNS ASK 20##########817_879.ltiapmyzmjxrvrts.info
- DNS ASK 20##########908_031.ltiapmyzmjxrvrts.info
- '%TEMP%\20230914t030817_879.exe'
- '%TEMP%\20230914t030908_031.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230914T030817_879.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230914T030908_031.exe