Техническая информация
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\decrypted_file.exe" "decrypted_file.exe" ENABLE
- %TEMP%\decrypted_file.exe
- %LOCALAPPDATA%\decrypted_file.exe
- %LOCALAPPDATA%\decrypted_file.exe
- 'localhost':5522
- '%TEMP%\decrypted_file.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%TEMP%\decrypted_file.exe" "decrypted_file.exe" ENABLE' (со скрытым окном)