Technical Information
- %WINDIR%\tasks\wow64.job
- <SYSTEM32>\tasks\wow64
- %WINDIR%\tasks\wow64.job
- <SYSTEM32>\tasks\wow64
- '19#.#06.191.223':80
- http://19#.#06.191.223/return.StaticLayout.Builder.module6_Ffaiifty.jpg
- 'localhost':61963
- 'localhost':55391
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAyAA==' (with hidden window)
- '<Full path to file>' start' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAyAA==