Technical Information
- '<SYSTEM32>\cmd.exe' /V:ON/C poweRShell -encoded J^ABZ^AHc^AaQ^A==
- '<SYSTEM32>\cmd.exe' /V:ON/C poweRShell -encoded J^ABZ^AHc^AaQ^A==' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encoded JABZAHcAaQA==