Technical Information
- 'no#####hoanggiatn.com':80
- http://no#####hoanggiatn.com/loader/uploads/withoutstartup_Nrsvrtuq.bmp
- DNS ASK no#####hoanggiatn.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' [System.Security.Principal.WindowsIdentity]::GetCurrent().Name' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAANwAwAA==' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' [System.Security.Principal.WindowsIdentity]::GetCurrent().Name
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAANwAwAA==