Техническая информация
- <SYSTEM32>\tasks\microsoft\windows\sys
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Microsoft\Windows\hyper-v.exe"
- %LOCALAPPDATA%\microsoft\windows\hyper-v.exe
- %LOCALAPPDATA%\hyper-v.ver
- 'sc#####oswaguuyo.xyz':1775
- 'sk#####ouussusyi.xyz':1775
- 'ua#####meqmwemas.xyz':1775
- http://ua######eqmwemas.xyz:1775/avast_update via ua#####meqmwemas.xyz
- http://ua######eqmwemas.xyz:1775/api/client_hello via ua#####meqmwemas.xyz
- DNS ASK iq#####uasswcmca.xyz
- DNS ASK kg#####qeacwaccu.xyz
- DNS ASK ug#####giimgmaaw.xyz
- DNS ASK km#####yqiwkeeci.xyz
- DNS ASK sc#####oswaguuyo.xyz
- DNS ASK sk#####ouussusyi.xyz
- DNS ASK ua#####meqmwemas.xyz
- '%WINDIR%\syswow64\systeminfo.exe'