Техническая информация
- '<SYSTEM32>\cmd.exe' /c ""C:\Documents and Settings\user\Exerwa\decode.bat""
- C:\documents and settings\user\exerwa\script.enc
- C:\documents and settings\user\exerwa\exec.enc
- C:\documents and settings\user\exerwa\decode.bat
- %HOMEPATH%\exerwa\exec.exe
- %HOMEPATH%\exerwa\script.ps1
- '<SYSTEM32>\certutil.exe' -f -decode exec.enc exec.exe
- '<SYSTEM32>\certutil.exe' -f -decode script.enc script.ps1