Technical Information
- $_ as $filename
- %TEMP%\d854.tmp\d8a3.tmp\d8a4.bat
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\D854.tmp\D8A3.tmp\D8A4.bat <Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\D854.tmp\D8A3.tmp\D8A4.bat <Full path to file>"