Technical Information
- <SYSTEM32>\tasks\thqymm
- <SYSTEM32>\tasks\microsoft\windows\tags\surrogateselector
- <SYSTEM32>\tasks\bvvfn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAHUAcwBlAHIAXABBAHAAcABEA...
- fqrsk.exe process, Amsi.dll module
- surrogateselector.exe process, Amsi.dll module
- fqrsk.exe process, ntdll.dll module
- surrogateselector.exe process, ntdll.dll module
- <SYSTEM32>\windowspowershell\v1.0\powershell.exe
- %LOCALAPPDATA%\tags\tkejdnk\surrogateselector.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- <SYSTEM32>\tasks\thqymm
- <SYSTEM32>\tasks\bvvfn
- DNS ASK mc.###iablinter.net
- '%LOCALAPPDATA%\tags\tkejdnk\surrogateselector.exe'