Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%ProgramFiles%\MicrosoftWindows'"
- %TEMP%\ixp000.tmp\seb-la~1.exe
- %TEMP%\ixp001.tmp\site.txt
- %TEMP%\ixp001.tmp\test.txt
- '%TEMP%\ixp000.tmp\seb-la~1.exe'
- '<SYSTEM32>\cmd.exe' /c type site.txt | cmd (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /S /D /c" type site.txt "
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\cmd.exe' /k type test.txt | cmd (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /S /D /c" type test.txt "