May 10, 2025
backup.bat: Deletes volume shadow copies to prevent data recovery.clean_dobat: Cleans up cached credentials and clears RDP history.close_apps.bat and kill_process.CMD: Repeatedly attempt to terminate various processes including backup, SQL, and cloud apps.delete.bat: Clears Windows event logs using built-in utilities.loggy_cleaner.dobat: Similar actions, removing various system logs and history.win.exe is the ransomware executable.NS.exe for network scanning and potential exploitation.medical.zip contained binaries for various operating systems (Linux, Windows, ESXi).