Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%APPDATA%'"
- %TEMP%\_mei29442\vcruntime140.dll
- %TEMP%\_mei29442\_asyncio.pyd
- %TEMP%\_mei29442\_bz2.pyd
- %TEMP%\_mei29442\_ctypes.pyd
- %TEMP%\_mei29442\_decimal.pyd
- %TEMP%\_mei29442\_hashlib.pyd
- %TEMP%\_mei29442\_lzma.pyd
- %TEMP%\_mei29442\_multiprocessing.pyd
- %TEMP%\_mei29442\_overlapped.pyd
- %TEMP%\_mei29442\_queue.pyd
- %TEMP%\_mei29442\_socket.pyd
- %TEMP%\_mei29442\_ssl.pyd
- %TEMP%\_mei29442\base_library.zip
- %TEMP%\_mei29442\libcrypto-3.dll
- %TEMP%\_mei29442\libffi-8.dll
- %TEMP%\_mei29442\libssl-3.dll
- %TEMP%\_mei29442\pyexpat.pyd
- %TEMP%\_mei29442\python311.dll
- %TEMP%\_mei29442\select.pyd
- %TEMP%\_mei29442\unicodedata.pyd
- 'localhost':49692
- DNS ASK sh##leta.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command "Get-MpPreference | Select-Object -ExpandProperty ExclusionPath"