Technical Information
- %TEMP%\20230926t014224_549.exe
- '20##########224_549.ltiapmyzmjxrvrts.info':80
- '20##########251_208.ltiapmyzmjxrvrts.info':80
- http://20##########224_549.ltiapmyzmjxrvrts.info/v4/20230926T014224_549.exe
- http://20##########251_208.ltiapmyzmjxrvrts.info/v4/20230926T014251_208.exe
- DNS ASK 20##########224_549.ltiapmyzmjxrvrts.info
- DNS ASK 20##########251_208.ltiapmyzmjxrvrts.info
- '%TEMP%\20230926t014224_549.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T014224_549.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T014251_208.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T014322_958.exe