: The process has been observed dropping legitimate-looking Windows executables to mask its activity and executing JS scripts to perform background tasks.
: The file is known to relocate itself upon execution to hide within the system and can drop additional executables to the system's drive root. Monoxidex86.exe.vir
: It may trigger applications like Notepad, a common behavior for ransomware to display ransom notes to the user. : The process has been observed dropping legitimate-looking