Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath '%WINDIR%','%ALLUSERSPROFILE%','C:\Users','C:\Program Files (x86)','C:\' -Force
- %HOMEPATH%\documents\frnhc8.exe
- 'an####.###-cn-beijing.aliyuncs.com':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?65##############
- 'an####.###-cn-beijing.aliyuncs.com':443
- DNS ASK an####.###-cn-beijing.aliyuncs.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath '%WINDIR%','%ALLUSERSPROFILE%','C:\Users','C:\Program Files (x86)','C:\' -Force' (with hidden window)