Technical Information
- %TEMP%\20230926t034809_197.exe
- %TEMP%\20230926t034835_820.exe
- %TEMP%\20230926t034904_782.exe
- '20##########809_197.ltiapmyzmjxrvrts.info':80
- '20##########835_820.ltiapmyzmjxrvrts.info':80
- '20##########904_782.ltiapmyzmjxrvrts.info':80
- '20##########943_722.ltiapmyzmjxrvrts.info':80
- http://20##########809_197.ltiapmyzmjxrvrts.info/v4/20230926T034809_197.exe
- http://20##########835_820.ltiapmyzmjxrvrts.info/v4/20230926T034835_820.exe
- http://20##########904_782.ltiapmyzmjxrvrts.info/v4/20230926T034904_782.exe
- http://20##########943_722.ltiapmyzmjxrvrts.info/v4/20230926T034943_722.exe
- DNS ASK 20##########809_197.ltiapmyzmjxrvrts.info
- DNS ASK 20##########835_820.ltiapmyzmjxrvrts.info
- DNS ASK 20##########904_782.ltiapmyzmjxrvrts.info
- DNS ASK 20##########943_722.ltiapmyzmjxrvrts.info
- '%TEMP%\20230926t034809_197.exe'
- '%TEMP%\20230926t034835_820.exe'
- '%TEMP%\20230926t034904_782.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034809_197.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034835_820.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034904_782.exe