Technical Information
- '%TEMP%\pr.exe'
- '%TEMP%\rewq.exe' http://dd##.ddns.net/pr.exe
- '%TEMP%\pr.exe' (downloaded from the Internet)
- '<SYSTEM32>\find.exe' /i "rewq.exe"
- '<SYSTEM32>\taskkill.exe' /im "praetorian.exe"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\install.cmd" "
- '<SYSTEM32>\tasklist.exe'
- %TEMP%\pr.exe
- %TEMP%\rewq.exe
- %TEMP%\install.cmd
- <DRIVERS>\etc\hosts
- 'dd##.ddns.net':80
- dd##.ddns.net/pr.exe
- DNS ASK dd##.ddns.net
- ClassName: '(null)' WindowName: '(null)'