Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABXAGIAcwB6AGMAagBpAGEAZQA9ACcARQBrAGcAbgByAHcAYwBwAHcAeAAnADsAJABZAHIAaQB1AGoAYQB4AGcAcgBvACAAPQAgACcAMgA2ADAAJwA7ACQAUQBtAG4AdABxAHQAbgBlAHQAcgA9ACcAVABvAGU...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1480
- %TEMP%\1138339.cvr
- 'ol#.#igbom.com':80
- 'ol#.#igbom.com':443
- 'to####thuong.com':443
- 'sw##.#unapanda.org':443
- http://ol#.#igbom.com/wp-snapshots/installer/CkYwk/
- 'ol#.#igbom.com':443
- 'to####thuong.com':443
- DNS ASK ne#.#os-sg.com
- DNS ASK ol#.#igbom.com
- DNS ASK to####thuong.com
- DNS ASK sw##.#unapanda.org
- DNS ASK ge####y.hadatha.net