Техническая информация
- %WINDIR%\explorer.exe
- <Текущая директория>\78d9fea679bcae67c1ffa9dcff355931_nativeransomewaredll_remotekey_winaes_overwrite_64.dll
- %ALLUSERSPROFILE%\cymulate\agent\attackslogs\edr\6981305bd122c39e5cf5324a\output_6981305bd122c39e5cf5324a_1772064965.txt
- %ALLUSERSPROFILE%\cymulate\agent\attackslogs\edr\6981305bd122c39e5cf5324a\output_6981305bd122c39e5cf5324a_1772064964.txt