Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'AQGWMCSIYOEUKAQ' = '<Full path to file>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'AGMSYEKQWCIOUAG' = '<Full path to file>'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'AGMSYEKQWCIOUAG' = '<Full path to file>'
- %WINDIR%\syswow64\windowspowershell\v1.0\_read_me.txt
- %WINDIR%\syswow64\windowspowershell\v1.0\decrypt_instructions.html
- %WINDIR%\syswow64\windowspowershell\v1.0\payload.bin
- %WINDIR%\syswow64\windowspowershell\v1.0\encrypted_data.dat
- %WINDIR%\syswow64\windowspowershell\v1.0\ransom_note.txt
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-4226853953-3309226944-3078887307-1000\74f7cd02b6b26f86e73a450f0a29850c_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %WINDIR%\syswow64\windowspowershell\v1.0\_read_me.txt
- %WINDIR%\syswow64\windowspowershell\v1.0\decrypt_instructions.html
- %WINDIR%\syswow64\windowspowershell\v1.0\payload.bin
- %WINDIR%\syswow64\windowspowershell\v1.0\encrypted_data.dat
- %WINDIR%\syswow64\windowspowershell\v1.0\ransom_note.txt