Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nOExIt -wIndOwstylE hIddEn -E JABEAGUAcwBrAHQAbwBwAFAAYQB0AGgAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAWwBTAHkAcwB0AGUAbQAuAEUAbg...
- %HOMEPATH%\desktop\eicar.txt
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nOExIt -wIndOwstylE hIddEn -E JABEAGUAcwBrAHQAbwBwAFAAYQB0AGgAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAWwBTAHkAcwB0AGUAbQAuAEUAbg...' (со скрытым окном)