Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'console_thread64' = '%APPDATA%\MysticLibary\console_thread64.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "C:\Users\$env:UserName\AppData\Roaming"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "C:\Users\Public"
- %APPDATA%\mysticlibary\console_thread64.exe
- 'ro#####sko.duckdns.org':7859
- DNS ASK ro#####sko.duckdns.org
- '%APPDATA%\mysticlibary\console_thread64.exe'