Technical Information
- %APPDATA%\0rrlkw05.ps1
- %APPDATA%\0rrlkw05.bat
- C:\users\public\documents\innjordzgfei.ps1
- C:\users\public\documents\innjordzgfei.ps1
- %APPDATA%\0rrlkw05.ps1
- %APPDATA%\0rrlkw05.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -file "%APPDATA%\0rRlkW05.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass -WindowStyle hidden -File C:\Users\Public\Documents\iNnJOrdzGFeI.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -c "cmd /q /c%APPDATA%\0rRlkW05.bat"
- '<SYSTEM32>\cmd.exe' /q /c%APPDATA%\0rRlkW05.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -c "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JEVycm9yQWN0aW9uUHJlZmVyZW5jZSA9ICJDb250aW51ZSIKCiRmeE5QWUhTaGIwTTNxUH...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass -WindowStyle hidden -c Continue = Continue