Technical Information
- %APPDATA%\sst5qbi2.ps1
- %APPDATA%\sst5qbi2.bat
- C:\users\public\documents\sanrxfvqmqjy.ps1
- C:\users\public\documents\sanrxfvqmqjy.ps1
- %APPDATA%\sst5qbi2.ps1
- %APPDATA%\sst5qbi2.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -file "%APPDATA%\SST5Qbi2.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass -WindowStyle hidden -File C:\Users\Public\Documents\SaNRxFvqmQJy.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -c "cmd /q /c%APPDATA%\SST5Qbi2.bat"
- '<SYSTEM32>\cmd.exe' /q /c%APPDATA%\SST5Qbi2.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -c "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JEVycm9yQWN0aW9uUHJlZmVyZW5jZSA9ICJDb250aW51ZSIKCiR4VVBxYjBxZEphTVJldn...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass -WindowStyle hidden -c Continue = Continue