Техническая информация
- C:\temp\utdlntte.ps1
- '17#.#5.142.190':80
- http://17#.#5.142.190/host/BAGG.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -File "C:\Temp\UTDLNTTE.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -File "C:\Temp\UTDLNTTE.ps1" (со скрытым окном)