Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -wINdOwstYlE hIddEN -E JABEAGUAcwBrAHQAbwBwAFAAYQB0AGgAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcg...
- %HOMEPATH%\desktop\eicar.txt
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -wINdOwstYlE hIddEN -E JABEAGUAcwBrAHQAbwBwAFAAYQB0AGgAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcg...' (with hidden window)