Technical Information
- <SYSTEM32>\tasks\service32.exe
- %TEMP%\service32.exe
- '5.###.132.160':56001
- '5.###.132.160':56001
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwBzAGUAcgB2AGkAYwBlADMAMgAuAGUAeABlACcAIAAtAEEAYwB0AGkAbwBuACAAK...