Техническая информация
- <SYSTEM32>\tasks\thqymm
- <SYSTEM32>\tasks\microsoft\windows\tags\surrogateselector
- <SYSTEM32>\tasks\bvvfn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAHUAcwBlAHIAXABBAHAAcABEA...
- Процесс fqrsk.exe, модуль Amsi.dll
- Процесс surrogateselector.exe, модуль Amsi.dll
- Процесс fqrsk.exe, модуль ntdll.dll
- Процесс surrogateselector.exe, модуль ntdll.dll
- <SYSTEM32>\windowspowershell\v1.0\powershell.exe
- %LOCALAPPDATA%\tags\tkejdnk\surrogateselector.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<Имя файла>.exe.log
- <SYSTEM32>\tasks\thqymm
- <SYSTEM32>\tasks\bvvfn
- DNS ASK mc.###iablinter.net
- '%LOCALAPPDATA%\tags\tkejdnk\surrogateselector.exe'