Technical Information
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Microsoft\Windows\fonthost.exe"
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\windows\fonthost.exe
- %LOCALAPPDATA%\fonthosts.ver
- %TEMP%\x3eg.0
- %TEMP%\x3eg.0-shm
- %TEMP%\x3eg.1
- %TEMP%\x3eg.2
- %TEMP%\x3eg.3
- %TEMP%\x3eg.4
- 'uk#####yyqyigueq.xyz':443
- http://uk######yqyigueq.xyz:443/api/client/new via uk#####yyqyigueq.xyz
- http://uk######yqyigueq.xyz:443/tasks/get_worker via uk#####yyqyigueq.xyz
- DNS ASK uk#####yyqyigueq.xyz
- '%WINDIR%\syswow64\systeminfo.exe'