Technical Information
- %TEMP%\20230925t202509_705.exe
- %TEMP%\20230925t202551_235.exe
- '20##########509_705.ltiapmyzmjxrvrts.info':80
- '20##########551_235.ltiapmyzmjxrvrts.info':80
- http://20##########509_705.ltiapmyzmjxrvrts.info/v4/20230925T202509_705.exe
- http://20##########551_235.ltiapmyzmjxrvrts.info/v4/20230925T202551_235.exe
- DNS ASK 20##########509_705.ltiapmyzmjxrvrts.info
- DNS ASK 20##########551_235.ltiapmyzmjxrvrts.info
- '%TEMP%\20230925t202509_705.exe'
- '%TEMP%\20230925t202551_235.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230925T202509_705.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230925T202551_235.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230925T202627_005.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230925T202712_080.exe