Technical Information
- %WINDIR%\syswow64\windowspowershell\v1.0\cc.pdf
- C:\users\public\calc.exe
- %LOCALAPPDATA%\adobe\color\profiles\wscrgb.icc
- %LOCALAPPDATA%\adobe\color\profiles\wsrgb.icc
- %LOCALAPPDATA%\adobe\color\acecache11.lst
- from <Full path to file> to C:\users\public\asfqgqqvebggabvqegvaqg
- 'C:\users\public\calc.exe'
- '%WINDIR%\syswow64\cmd.exe' " /c " <SYSTEM32>\WindowsPowerShell\v1.0\cc.pdf
- '%ProgramFiles%\windowsapps\microsoft.windowscalculator_10.1906.55.0_x64__8wekyb3d8bbwe\calculator.exe' -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "<SYSTEM32>\WindowsPowerShell\v1.0\cc.pdf"
- '%WINDIR%\syswow64\cmd.exe' " /c " <SYSTEM32>\WindowsPowerShell\v1.0\cc.pdf' (with hidden window)