Техническая информация
- '%APPDATA%\microsoft\windows\templates\hloek.exe'
- hloek.exe
- %APPDATA%\microsoft\windows\templates\hloek.exe
- C:\users\public\sysq.ps1
- http://www.ce###lus.com/CRL/class2.crl
- DNS ASK pl##.root.gg
- DNS ASK ce###lus.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "C:\Users\Public\sysq.ps1"