Technical Information
- %TEMP%\20230929t222832_501.exe
- %TEMP%\20230929t222922_701.exe
- '20##########832_501.ltiapmyzmjxrvrts.info':80
- '20##########922_701.ltiapmyzmjxrvrts.info':80
- '20##########000_191.ltiapmyzmjxrvrts.info':80
- http://20##########832_501.ltiapmyzmjxrvrts.info/v4/20230929T222832_501.exe
- http://20##########922_701.ltiapmyzmjxrvrts.info/v4/20230929T222922_701.exe
- http://20##########000_191.ltiapmyzmjxrvrts.info/v4/20230929T223000_191.exe
- DNS ASK 20##########832_501.ltiapmyzmjxrvrts.info
- DNS ASK 20##########922_701.ltiapmyzmjxrvrts.info
- DNS ASK 20##########000_191.ltiapmyzmjxrvrts.info
- '%TEMP%\20230929t222832_501.exe'
- '%TEMP%\20230929t222922_701.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230929T222832_501.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230929T222922_701.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230929T223000_191.exe