Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\cwlxgdc.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- http://dl#.#oxi.net/drive/2018/11/12/0027/3642/1777210/10/7f00c6173d.txt
- DNS ASK dl#.#oxi.net
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' copy-item -path '<Full path to file>' -destination '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\cwlXGDC.exe'' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' copy-item -path '<Full path to file>' -destination '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\cwlXGDC.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'