Sof002.rar
New entries in the Windows Registry Run keys or new scheduled tasks.
Malicious shortcuts that trigger PowerShell commands to bypass standard security filters. Indicators of Compromise (IoCs) SOF002.rar
If you executed the file, assume your passwords have been compromised. Change them from a clean device. For Organizations New entries in the Windows Registry Run keys
If you have interacted with this file, look for the following signs of infection: SOF002.rar