Technical Information
- %TEMP%\20230926t034732_552.exe
- %TEMP%\20230926t034825_742.exe
- '20##########732_552.ltiapmyzmjxrvrts.info':80
- '20##########825_742.ltiapmyzmjxrvrts.info':80
- '20##########909_402.ltiapmyzmjxrvrts.info':80
- http://20##########732_552.ltiapmyzmjxrvrts.info/v4/20230926T034732_552.exe
- http://20##########825_742.ltiapmyzmjxrvrts.info/v4/20230926T034825_742.exe
- http://20##########909_402.ltiapmyzmjxrvrts.info/v4/20230926T034909_402.exe
- DNS ASK 20##########732_552.ltiapmyzmjxrvrts.info
- DNS ASK 20##########825_742.ltiapmyzmjxrvrts.info
- DNS ASK 20##########909_402.ltiapmyzmjxrvrts.info
- '%TEMP%\20230926t034732_552.exe'
- '%TEMP%\20230926t034825_742.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034732_552.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034825_742.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230926T034909_402.exe