Hey everyone,
I’m leaning toward DLL side-loading or a patched executable . Someone likely replaced the legitimate qbwebpatch.exe with a malicious version that maintains the same file name and description. The legitimate version should never call PowerShell directly.
T3chAdmin (Level 15)