Technical Information
- %TEMP%\20230926t013540_896.exe
- %TEMP%\20230926t013637_520.exe
- '20##########540_896.ltiapmyzmjxrvrts.info':80
- '20##########637_520.ltiapmyzmjxrvrts.info':80
- http://20##########540_896.ltiapmyzmjxrvrts.info/v4/20230926T013540_896.exe
- http://20##########637_520.ltiapmyzmjxrvrts.info/v4/20230926T013637_520.exe
- DNS ASK 20##########540_896.ltiapmyzmjxrvrts.info
- DNS ASK 20##########637_520.ltiapmyzmjxrvrts.info
- '%TEMP%\20230926t013540_896.exe'
- '%TEMP%\20230926t013637_520.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T013540_896.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T013637_520.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T013741_905.exe