Technical Information
- User Account Control (UAC)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force
- <SYSTEM32>\calc.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\ilasm.exe
- <SYSTEM32>\notepad.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\ngen.exe
- wab.exe
- %ALLUSERSPROFILE%\remcos\logs.dat
- '23.#5.60.82':4445
- '%ProgramFiles(x86)%\windows mail\wab.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "<Full path to file>" -Force' (with hidden window)