Technical Information
- %TEMP%\20230926t013745_891.exe
- %TEMP%\20230926t013826_364.exe
- %TEMP%\20230926t013902_500.exe
- '20##########745_891.ltiapmyzmjxrvrts.info':80
- '20##########826_364.ltiapmyzmjxrvrts.info':80
- '20##########902_500.ltiapmyzmjxrvrts.info':80
- '20##########938_889.ltiapmyzmjxrvrts.info':80
- http://20##########745_891.ltiapmyzmjxrvrts.info/v4/20230926T013745_891.exe
- http://20##########826_364.ltiapmyzmjxrvrts.info/v4/20230926T013826_364.exe
- http://20##########902_500.ltiapmyzmjxrvrts.info/v4/20230926T013902_500.exe
- DNS ASK 20##########745_891.ltiapmyzmjxrvrts.info
- DNS ASK 20##########826_364.ltiapmyzmjxrvrts.info
- DNS ASK 20##########902_500.ltiapmyzmjxrvrts.info
- DNS ASK 20##########938_889.ltiapmyzmjxrvrts.info
- '%TEMP%\20230926t013745_891.exe'
- '%TEMP%\20230926t013826_364.exe'
- '%TEMP%\20230926t013902_500.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T013745_891.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T013826_364.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T013902_500.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T013938_889.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T014008_036.exe