Technical Information
- <SYSTEM32>\tasks\msiedgee.exe
- %APPDATA%\msiedgee.exe
- 'ne#####rsas.kozow.com':56001
- 'ne#####rsas.kozow.com':56001
- DNS ASK ne#####rsas.kozow.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwBtAHMAaQBlAGQAZwBlAGUALgBlAHgAZQAnACAALQBBAGMAdABpAG8AbgAgACgAT...