Техническая информация
- <SYSTEM32>\tasks\microsoft\windows\sys
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Microsoft\Windows\vspkgsrv.exe"
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\windows\vspkgsrv.exe
- %LOCALAPPDATA%\hyper-v.ver
- %TEMP%\xas.0
- %TEMP%\xas.0-shm
- %TEMP%\xas.1
- %TEMP%\xas.2
- %TEMP%\xas.3
- %TEMP%\xas.4
- 'cm#####iwwksmcsw.xyz':443
- http://cm######wwksmcsw.xyz:443/api/client/new via cm#####iwwksmcsw.xyz
- http://cm######wwksmcsw.xyz:443/tasks/get_worker via cm#####iwwksmcsw.xyz
- DNS ASK ma#####maacckuow.xyz
- DNS ASK ye#####aewokgioa.xyz
- DNS ASK cm#####iwwksmcsw.xyz
- '%WINDIR%\syswow64\systeminfo.exe'