Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noP -sta -enc dwBoAG8AYQBtAGkAIAA+ACAAQwA6AFwAVQBzAGUAcgBzAFwAagBhAGMAawBcAEQAZQBzAGsAdABvAHAAXAAxADIAMwAuAHQAeAB0AA==
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noP -sta -enc dwBoAG8AYQBtAGkAIAA+ACAAQwA6AFwAVQBzAGUAcgBzAFwAagBhAGMAawBcAEQAZQBzAGsAdABvAHAAXAAxADIAMwAuAHQAeAB0AA==' (with hidden window)