Technical Information
- %TEMP%\20230926t034732_729.exe
- %TEMP%\20230926t034814_926.exe
- '20##########732_729.ltiapmyzmjxrvrts.info':80
- '20##########814_926.ltiapmyzmjxrvrts.info':80
- '20##########853_413.ltiapmyzmjxrvrts.info':80
- http://20##########732_729.ltiapmyzmjxrvrts.info/v4/20230926T034732_729.exe
- http://20##########814_926.ltiapmyzmjxrvrts.info/v4/20230926T034814_926.exe
- http://20##########853_413.ltiapmyzmjxrvrts.info/v4/20230926T034853_413.exe
- DNS ASK 20##########732_729.ltiapmyzmjxrvrts.info
- DNS ASK 20##########814_926.ltiapmyzmjxrvrts.info
- DNS ASK 20##########853_413.ltiapmyzmjxrvrts.info
- '%TEMP%\20230926t034732_729.exe'
- '%TEMP%\20230926t034814_926.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034732_729.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034814_926.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034853_413.exe