Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'CLoaderService' = '"<Full path to file>" --embedded-browser-webview=1'
- <SYSTEM32>\tasks\cloaderupdate
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "Add-MpPreference -ExclusionPath '%APPDATA%\Microsoft\Windows\cloader'"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -Command "Add-MpPreference -ExclusionPath '<Current directory>'"
- %APPDATA%\microsoft\windows\cloader\svc.exe
- %APPDATA%\microsoft\windows\cloader\config.json
- '91.##.242.220':8081
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN CLoaderUpdate /TR "\"<Full path to file>\" --embedded-browser-webview=1" /RL HIGHEST