Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Aehbhnj' = '"%APPDATA%\Btlvyulq\Aehbhnj.exe"'
- %APPDATA%\btlvyulq\aehbhnj.exe
- '19#.#06.191.223':80
- http://19#.#06.191.223/TextView.setBreakStrategy.module16_Kisuscnw.jpg
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAyAA==' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAyAA==