Техническая информация
- C:\temp\ahuujldl.ps1
- '17#.#5.134.79':80
- http://17#.#5.134.79/HOST/DEVNEW.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -File "C:\Temp\AHUUJLDL.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -File "C:\Temp\AHUUJLDL.ps1" (со скрытым окном)