Technical Information
- https://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1
- %TEMP%\afldvsb.bat
- nul
- %TEMP%\test.bat
- 'ra#.####ubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\afldvsb.bat" "
- '%WINDIR%\syswow64\certutil.exe' -f -decode "%TEMP%\afldvsb.bat" "%LOCALAPPDATA%\Temp/test.bat"