Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '<Current directory>' -Force"
- nul
- %TEMP%\h_tmp
- %TEMP%\h_data.txt
- %TEMP%\h_data.zip
- %TEMP%\h_tmp
- %TEMP%\h_data.txt
- %TEMP%\h_data.zip
- %TEMP%\h_tmp
- 'localhost':49695
- 'localhost':49698
- 'localhost':49701
- 'localhost':49695
- 'localhost':49696
- 'localhost':49698
- 'localhost':49699
- 'localhost':49701
- 'localhost':49702
- DNS ASK ap#.##legram.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Compress-Archive -Path '%TEMP%\h_data.txt' -DestinationPath '%TEMP%\h_data.zip' -Force"
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath '<Current directory>' -Force" > nul 2>&1
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Compress-Archive -Path '%TEMP%\h_data.txt' -DestinationPath '%TEMP%\h_data.zip' -Force" > nul 2>&1