Technical Information
- '%TEMP%\cHUKUuJQKNoyAhWb.exe' x MSyXVDPhtlWxgFpX.zip -pq1w2e3r4t5y6u7i8o9 -y
- '%TEMP%\cHUKUuJQKNoyAhWb.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /k c: & cd\ & cd %HOMEPATH%\Local Settings\Temp & cHUKUuJQKNoyAhWb.exe x MSyXVDPhtlWxgFpX.zip -pq1w2e3r4t5y6u7i8o9 -y & exit
- %TEMP%\MSyXVDPhtlWxgFpX.zip
- %TEMP%\cHUKUuJQKNoyAhWb.exe
- 'ho####oodvips.com':80
- http://ho####oodvips.com/newliga/capitao.jpg
- http://ho####oodvips.com/liga/wosts.jpg
- DNS ASK ho####oodvips.com