Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths] '%ALLUSERSPROFILE%\Microsoft\Windows\Security\Driver_Modules_1048' = ''
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath \"%ALLUSERSPROFILE%\Microsoft\Windows\Security\Driver_Modules_1048\""
- %TEMP%\runtime_log_20412.txt
- %ALLUSERSPROFILE%\microsoft\windows\security\driver_modules_1048\payload.exe.enc
- %ALLUSERSPROFILE%\microsoft\windows\security\driver_modules_1048\windivert.exe.enc
- %ALLUSERSPROFILE%\microsoft\windows\security\driver_modules_1048\payload.exe
- %ALLUSERSPROFILE%\microsoft\windows\security\driver_modules_1048\payload.exe.enc
- DNS ASK kr##tex.com
- DNS ASK ww####.kryptex.com
- '%ALLUSERSPROFILE%\microsoft\windows\security\driver_modules_1048\payload.exe'