Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Set-MpPreference -DisableRealtimeMonitoring $true -DisableIOAVProtection $true -DisableIntrusionPreventionSystem $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -Enabl...
- %TEMP%\python-3.12.4-amd64.exe
- 'localhost':49555
- 'localhost':64568
- 'localhost':53183
- 'localhost':55760
- '%TEMP%\python-3.12.4-amd64.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ipconfig /release (со скрытым окном)
- '%WINDIR%\syswow64\ipconfig.exe' /release
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAG0AZgB2AGIAYgBcAHgAeQB0AGwALgBlAHgAZQA7ACAAQQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4... (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Set-MpPreference -DisableRealtimeMonitoring $true -DisableIOAVProtection $true -DisableIntrusionPreventionSystem $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -Enabl... (со скрытым окном)