Stage1.exe is executed using PowerShell within the network. This could allow the malware to execute on targeted machines. The presence of Finish.exe suggests potential prior compromise, while Exclude.exe indicates a possible exclusion of the machine.
#WORLD #English #IE
Read more at Trend Micro