Technical Information
- <SYSTEM32>\tasks\microsoft\windows\sys
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Microsoft\Windows\systemtask.exe"
- %LOCALAPPDATA%\microsoft\windows\systemtask.exe
- %LOCALAPPDATA%\hyper-v.ver
- %TEMP%\x1do.0
- %TEMP%\x1do.1
- %TEMP%\x1do.1-shm
- %TEMP%\x1do.3
- 'qc#####ukogkeuge.xyz':443
- http://qc######kogkeuge.xyz:443/avast_update via qc#####ukogkeuge.xyz
- http://qc######kogkeuge.xyz:443/api/client_hello via qc#####ukogkeuge.xyz
- DNS ASK es#####sukcuoico.xyz
- DNS ASK oe#####sewamggaa.xyz
- DNS ASK yy#####gygqayqys.xyz
- DNS ASK cg#####uwiikcwug.xyz
- DNS ASK qc#####ukogkeuge.xyz
- '%WINDIR%\syswow64\systeminfo.exe'