Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NonInteractive -Command Add-MpPreference -ExclusionPath 'C:\\'
- %WINDIR%\syswow64\microsoft\1\vshost.exe
- %WINDIR%\syswow64\microsoft\2\system.exe
- %WINDIR%\syswow64\microsoft\3\xt4yo8x.exe
- conout$
- '19#.#6.93.47':80
- '19#.#6.93.47':443
- '19#.#6.93.47':443
- '%WINDIR%\syswow64\microsoft\1\vshost.exe' --monitor 1 --parent 3884
- '%WINDIR%\syswow64\microsoft\2\system.exe' --monitor 2 --parent 3884
- '%WINDIR%\syswow64\microsoft\3\xt4yo8x.exe' --monitor 3 --parent 3884
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NonInteractive -Command Add-MpPreference -ExclusionPath 'C:\\' (со скрытым окном)