Техническая информация
- %APPDATA%\w6pgout7.ps1
- %APPDATA%\w6pgout7.bat
- C:\users\public\documents\tgbzkuoxdltd.ps1
- C:\users\public\documents\tgbzkuoxdltd.ps1
- %APPDATA%\w6pgout7.ps1
- %APPDATA%\w6pgout7.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -file "%APPDATA%\W6pgOUt7.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass -WindowStyle hidden -File C:\Users\Public\Documents\tGbZKUOxdLTD.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -c "cmd /q /c%APPDATA%\W6pgOUt7.bat"
- '<SYSTEM32>\cmd.exe' /q /c%APPDATA%\W6pgOUt7.bat
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle hidden -c "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JEVycm9yQWN0aW9uUHJlZmVyZW5jZSA9ICJDb250aW51ZSIKCiRJYUUxenVjUTZ3WmxiZU...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noprofile -executionpolicy bypass -WindowStyle hidden -c Continue = Continue