Technical Information
- <SYSTEM32>\wbadmin.exe
- %APPDATA%\hnta\container
- %WINDIR%\logs\windowsbackup\wbadmin.0.etl
- from %WINDIR%\logs\windowsbackup\wbadmin.0.etl to %WINDIR%\logs\windowsbackup\wbadmin.1.etl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Set-MpPreference -EnableControlledFolderAccess Disabled' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Test-Connection google.com' (with hidden window)
- '<SYSTEM32>\werfault.exe' -u -p 2132 -s 676' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c vssadmin.exe delete shadows /all /quiet
- '<SYSTEM32>\cmd.exe' /c icacls "C:\*" /grant Everyone:F /T /C /Q
- '<SYSTEM32>\wbadmin.exe' DELETE SYSTEMSTATEBACKUP
- '<SYSTEM32>\icacls.exe' "C:\*" /grant Everyone:F /T /C /Q
- '<SYSTEM32>\wbadmin.exe' DELETE SYSTEMSTATEBACKUP -deleteOldest
- '<SYSTEM32>\wbadmin.exe' DELETE SYSTEMSTATEBACKUP -keepVersions:0
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Set-MpPreference -EnableControlledFolderAccess Disabled
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Test-Connection google.com