Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '\\AppData\\Local\\Microsoft\\Windows\\Shell'"
- %LOCALAPPDATA%\microsoft\windows\shell\shellhost.exe
- <Текущая директория>\sodium.zip
- <Текущая директория>\version.txt
- 'cl######ttings.roblox.com':443
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'x1.#.lencr.org':80
- 'pa###bin.com':443
- 'dr##box.com':443
- http://x1.#.lencr.org/
- 'cl######ttings.roblox.com':443
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'pa###bin.com':443
- 'dr##box.com':443
- DNS ASK cl######ttings.roblox.com
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- DNS ASK x1.#.lencr.org
- DNS ASK pa###bin.com
- DNS ASK dr##box.com
- '%LOCALAPPDATA%\microsoft\windows\shell\shellhost.exe'
- '<SYSTEM32>\cmd.exe' /c powershell -Command "Add-MpPreference -ExclusionPath '\\AppData\\Local\\Microsoft\\Windows\\Shell'"