This describes a fileless virus, which commonly injects PowerShell commands into existing scripts.
Security information and event management (SIEM) systems can be configured to send alerts when PowerShell commands are detected.
Ransomware typically encrypts data and the attacker then demands payment as ransom, but there isn’t any indication that a ransom is requested in this scenario.
The fileless virus may have joined the computer to a botnet and the traffic to and from the unknown IP address may be a connection to a command and control server. However, there isn’t enough information to make this conclusion.
A rootkit is a program or group of programs that provide root-level access to a system and hides itself to evade detection.