Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\securityservice.lnk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "$now = [DateTime]::Now; $next = $now.AddHours(24); $wmi_time = $next.ToUniversalTime().ToString('yyyyMMddHHmmss.ffffff+000'); $f...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "$consumer = ([wmiclass]'root\subscription:CommandLineEventConsumer').CreateInstance(); $consumer.Name = 'SystemConsumer6f'; $con...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "$filter = Get-WmiObject -Namespace root\subscription -Class __EventFilter -Filter \"Name='SystemTimer6f'\"; $consumer = Get-WmiO...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "$amol = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name;;if ($amol -match '@') { $amol = $amol.Split('@')[0] };if...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "$hfln = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name;;if ($hfln -match '@') { $hfln = $hfln.Split('@')[0] };if...