Техническая информация
- <SYSTEM32>\tasks\microsoft\windows\sys
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Microsoft\Windows\hyper-v.exe"
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\windows\hyper-v.exe
- %LOCALAPPDATA%\hyper-v.ver
- %TEMP%\x2o8.0
- %TEMP%\x2o8.1
- %TEMP%\x2o8.2
- %TEMP%\x2o8.3
- 'uu#####mkuymmqou.xyz':443
- http://uu######kuymmqou.xyz:443/api/client/new via uu#####mkuymmqou.xyz
- DNS ASK uu#####mkuymmqou.xyz
- '%WINDIR%\syswow64\systeminfo.exe'