Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\httcazpr""
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath "C:\Users""
- %TEMP%\nwbgigl.txt
- '17#.#6.152.62':5858
- '<DNS_SERVER>':53
- '<SYSTEM32>\cmd.exe' /C powershell.exe -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\httcazpr""
- '<SYSTEM32>\cmd.exe' /C powershell.exe -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath "C:\Users""
- '<SYSTEM32>\cmd.exe' /C powershell.exe -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\httcazpr""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C powershell.exe -NoProfile -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath "C:\Users""' (with hidden window)