Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) cABpAG4AZwAgAC0AdAAgADEAOQAyAC4AMQA2ADgALgAxAC4AMQAgAA==
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) cABpAG4AZwAgAC0AdAAgADEAOQAyAC4AMQA2ADgALgAxAC4AMQAgAA==' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc cABpAG4AZwAgAC0AdAAgADEAOQAyAC4AMQA2ADgALgAxAC4AMQAgAA==
- '<SYSTEM32>\ping.exe' -t 192.168.1.1