Technical Information
- %TEMP%\20230915t215644_495.exe
- '20##########644_495.ltiapmyzmjxrvrts.info':80
- '20##########713_880.ltiapmyzmjxrvrts.info':80
- http://20##########644_495.ltiapmyzmjxrvrts.info/v4/20230915T215644_495.exe
- http://20##########713_880.ltiapmyzmjxrvrts.info/v4/20230915T215713_880.exe
- DNS ASK 20##########644_495.ltiapmyzmjxrvrts.info
- DNS ASK 20##########713_880.ltiapmyzmjxrvrts.info
- '%TEMP%\20230915t215644_495.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230915T215644_495.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230915T215713_880.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230915T215805_825.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230915T215855_494.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230915T215957_314.exe