Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe
- %APPDATA%\file\file.exe
- '%WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %WINDIR%\sysnative\WindowsPowerShell\v1.0\powershell.exe -Command "[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String('ZgB1AG4AYwB0AGkAbwBuACAARwBlAHQALQBEAGUAYwBvA...
- '%WINDIR%\syswow64\cmd.exe' /c mkdir "%APPDATA%\file"
- '%WINDIR%\syswow64\cmd.exe' /c copy "<Полный путь к файлу>" "%APPDATA%\file\file.exe"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String('ZgB1AG4AYwB0AGkAbwBuACAARwBlAHQALQBEAGUAYwBvAG0AcAByAGUAcwBzAGUAZABCAHkAdABlAEEAcgByAGEAeQAgAHsACgAKAAkAW...