Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '<Full path to file>'"
- %TEMP%\content\5372-5344-<File name>.exe-22-54-23-565.dump
- %TEMP%\content\5372-5344-<File name>.exe-22-54-28-862.dump
- <Current directory>\config.json
- <Current directory>\logs\errorlogs.txt
- 'clients3.google.com':443
- 'to#########-default-rtdb.firebaseio.com':443
- 'ke##uth.win':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'clients3.google.com':443
- 'to#########-default-rtdb.firebaseio.com':443
- 'ke##uth.win':443
- DNS ASK clients3.google.com
- DNS ASK to#########-default-rtdb.firebaseio.com
- DNS ASK ke##uth.win
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Get-MpPreference | Select-Object -ExpandProperty ExclusionPath"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '<Full path to file>'"' (with hidden window)