Technical Information
- %TEMP%\20230925t234607_654.exe
- %TEMP%\20230925t234638_297.exe
- %TEMP%\20230925t234706_567.exe
- '20##########607_654.ltiapmyzmjxrvrts.info':80
- '20##########638_297.ltiapmyzmjxrvrts.info':80
- '20##########706_567.ltiapmyzmjxrvrts.info':80
- '20##########741_221.ltiapmyzmjxrvrts.info':80
- http://20##########607_654.ltiapmyzmjxrvrts.info/v4/20230925T234607_654.exe
- http://20##########638_297.ltiapmyzmjxrvrts.info/v4/20230925T234638_297.exe
- http://20##########706_567.ltiapmyzmjxrvrts.info/v4/20230925T234706_567.exe
- http://20##########741_221.ltiapmyzmjxrvrts.info/v4/20230925T234741_221.exe
- DNS ASK 20##########607_654.ltiapmyzmjxrvrts.info
- DNS ASK 20##########638_297.ltiapmyzmjxrvrts.info
- DNS ASK 20##########706_567.ltiapmyzmjxrvrts.info
- DNS ASK 20##########741_221.ltiapmyzmjxrvrts.info
- '%TEMP%\20230925t234607_654.exe'
- '%TEMP%\20230925t234638_297.exe'
- '%TEMP%\20230925t234706_567.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230925T234607_654.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230925T234638_297.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230925T234706_567.exe