{"id":478486,"date":"2023-08-09T09:33:31","date_gmt":"2023-08-09T09:33:31","guid":{"rendered":""},"modified":"2023-09-05T11:16:50","modified_gmt":"2023-09-05T11:16:50","slug":"poweliks","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/vn\/wiki\/poweliks\/","title":{"rendered":"Poweliks"},"content":{"rendered":"<p>Poweliks l\u00e0 m\u1ed9t lo\u1ea1i ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i thu\u1ed9c danh m\u1ee5c ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i kh\u00f4ng c\u00f3 t\u1ec7p. Kh\u00f4ng gi\u1ed1ng nh\u01b0 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i truy\u1ec1n th\u1ed1ng l\u00e2y nhi\u1ec5m c\u00e1c t\u1ec7p tr\u00ean m\u00e1y t\u00ednh, Poweliks ch\u1ec9 t\u1ed3n t\u1ea1i trong s\u1ed5 \u0111\u0103ng k\u00fd Windows, khi\u1ebfn vi\u1ec7c ph\u00e1t hi\u1ec7n v\u00e0 lo\u1ea1i b\u1ecf tr\u1edf n\u00ean kh\u00f3 kh\u0103n. N\u00f3 \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n l\u1ea7n \u0111\u1ea7u ti\u00ean v\u00e0o n\u0103m 2014 v\u00e0 k\u1ec3 t\u1eeb \u0111\u00f3 \u0111\u00e3 ph\u00e1t tri\u1ec3n th\u00e0nh m\u1ed1i \u0111e d\u1ecda \u0111\u00e1ng g\u1eddm \u0111\u1ed1i v\u1edbi c\u00e1c h\u1ec7 th\u1ed1ng m\u00e1y t\u00ednh.<\/p>\n<h2>L\u1ecbch s\u1eed v\u1ec1 ngu\u1ed3n g\u1ed1c c\u1ee7a Poweliks v\u00e0 l\u1ea7n \u0111\u1ea7u ti\u00ean \u0111\u1ec1 c\u1eadp \u0111\u1ebfn n\u00f3.<\/h2>\n<p>Ngu\u1ed3n g\u1ed1c c\u1ee7a Poweliks v\u1eabn c\u00f2n kh\u00e1 m\u01a1 h\u1ed3, nh\u01b0ng n\u00f3 \u0111\u01b0\u1ee3c cho l\u00e0 \u0111\u01b0\u1ee3c t\u1ea1o ra b\u1edfi m\u1ed9t nh\u00f3m t\u1ed9i ph\u1ea1m m\u1ea1ng tinh vi nh\u1eb1m khai th\u00e1c kh\u1ea3 n\u0103ng t\u00e0ng h\u00ecnh c\u1ee7a ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i kh\u00f4ng d\u00f9ng t\u1ec7p. T\u00e0i li\u1ec7u \u0111\u1ea7u ti\u00ean \u0111\u1ec1 c\u1eadp \u0111\u1ebfn Poweliks c\u00f3 th\u1ec3 b\u1eaft ngu\u1ed3n t\u1eeb m\u1ed9t b\u00e1o c\u00e1o nghi\u00ean c\u1ee9u \u0111\u01b0\u1ee3c xu\u1ea5t b\u1ea3n v\u00e0o n\u0103m 2014 b\u1edfi c\u00e1c chuy\u00ean gia b\u1ea3o m\u1eadt t\u1ea1i Microsoft. K\u1ec3 t\u1eeb \u0111\u00f3, n\u00f3 \u0111\u00e3 tr\u1edf th\u00e0nh ch\u1ee7 \u0111\u1ec1 \u0111\u01b0\u1ee3c c\u00e1c chuy\u00ean gia an ninh m\u1ea1ng quan t\u00e2m do nh\u1eefng \u0111\u1eb7c \u0111i\u1ec3m \u0111\u1ed9c \u0111\u00e1o v\u00e0 k\u1ef9 thu\u1eadt l\u1ea9n tr\u00e1nh c\u1ee7a n\u00f3.<\/p>\n<h2>Th\u00f4ng tin chi ti\u1ebft v\u1ec1 Poweliks. M\u1edf r\u1ed9ng ch\u1ee7 \u0111\u1ec1 Poweliks.<\/h2>\n<p>Poweliks ch\u1ee7 y\u1ebfu nh\u1eafm m\u1ee5c ti\u00eau v\u00e0o c\u00e1c h\u1ec7 th\u1ed1ng d\u1ef1a tr\u00ean Windows v\u00e0 \u0111\u01b0\u1ee3c ph\u00e2n ph\u1ed1i th\u00f4ng qua nhi\u1ec1u ph\u01b0\u01a1ng ti\u1ec7n kh\u00e1c nhau, ch\u1eb3ng h\u1ea1n nh\u01b0 t\u1ec7p \u0111\u00ednh k\u00e8m email \u0111\u1ed9c h\u1ea1i, trang web b\u1ecb nhi\u1ec5m ho\u1eb7c b\u1ed9 c\u00f4ng c\u1ee5 khai th\u00e1c. Sau khi l\u00e2y nhi\u1ec5m v\u00e0o h\u1ec7 th\u1ed1ng, n\u00f3 s\u1ebd thao t\u00fang s\u1ed5 \u0111\u0103ng k\u00fd Windows \u0111\u1ec3 t\u1ea1o ra s\u1ef1 t\u1ed3n t\u1ea1i l\u00e2u d\u00e0i v\u00e0 th\u1ef1c thi t\u1ea3i tr\u1ecdng \u0111\u1ed9c h\u1ea1i trong b\u1ed9 nh\u1edb. B\u1eb1ng c\u00e1ch tr\u00e1nh s\u1eed d\u1ee5ng c\u00e1c t\u1ec7p, Poweliks tr\u00e1nh \u0111\u01b0\u1ee3c ph\u1ea7n m\u1ec1m ch\u1ed1ng vi-r\u00fat v\u00e0 ch\u1ed1ng ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i truy\u1ec1n th\u1ed1ng, khi\u1ebfn vi\u1ec7c ph\u00e1t hi\u1ec7n v\u00e0 lo\u1ea1i b\u1ecf tr\u1edf n\u00ean kh\u00f3 kh\u0103n.<\/p>\n<p>Ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i n\u00e0y ho\u1ea1t \u0111\u1ed9ng l\u00e9n l\u00fat, khi\u1ebfn ng\u01b0\u1eddi d\u00f9ng kh\u00f3 nh\u1eadn th\u1ea5y b\u1ea5t k\u1ef3 ho\u1ea1t \u0111\u1ed9ng \u0111\u00e1ng ng\u1edd n\u00e0o. Poweliks c\u00f3 th\u1ec3 tham gia v\u00e0o c\u00e1c ho\u1ea1t \u0111\u1ed9ng \u0111\u1ed9c h\u1ea1i nh\u01b0 \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u, ghi nh\u1eadt k\u00fd thao t\u00e1c b\u00e0n ph\u00edm v\u00e0 t\u1ea3i c\u00e1c t\u1ea3i tr\u1ecdng c\u00f3 h\u1ea1i kh\u00e1c xu\u1ed1ng h\u1ec7 th\u1ed1ng b\u1ecb nhi\u1ec5m.<\/p>\n<h2>C\u1ea5u tr\u00fac b\u00ean trong c\u1ee7a Poweliks. C\u00e1ch th\u1ee9c ho\u1ea1t \u0111\u1ed9ng c\u1ee7a Poweliks.<\/h2>\n<p>Poweliks \u0111\u01b0\u1ee3c thi\u1ebft k\u1ebf \u0111\u1ec3 duy tr\u00ec tr\u1ea1ng th\u00e1i l\u01b0u tr\u00fa trong b\u1ed9 nh\u1edb, ngh\u0129a l\u00e0 n\u00f3 kh\u00f4ng \u0111\u1ec3 l\u1ea1i b\u1ea5t k\u1ef3 t\u1ec7p n\u00e0o tr\u00ean \u1ed5 c\u1ee9ng c\u1ee7a h\u1ec7 th\u1ed1ng b\u1ecb nhi\u1ec5m. Thay v\u00e0o \u0111\u00f3, n\u00f3 t\u1ef1 nh\u00fang v\u00e0o s\u1ed5 \u0111\u0103ng k\u00fd Windows, \u0111\u1eb7c bi\u1ec7t l\u00e0 trong c\u00e1c kh\u00f3a \u201cShell\u201d ho\u1eb7c \u201cUserinit\u201d. C\u00e1c kh\u00f3a n\u00e0y r\u1ea5t c\u1ea7n thi\u1ebft \u0111\u1ec3 h\u1ec7 \u0111i\u1ec1u h\u00e0nh ho\u1ea1t \u0111\u1ed9ng b\u00ecnh th\u01b0\u1eddng v\u00e0 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i l\u1ee3i d\u1ee5ng \u0111i\u1ec1u n\u00e0y \u0111\u1ec3 duy tr\u00ec s\u1ef1 t\u1ed3n t\u1ea1i.<\/p>\n<p>Sau khi h\u1ec7 th\u1ed1ng b\u1ecb nhi\u1ec5m, Poweliks s\u1ebd ti\u00eam tr\u1ef1c ti\u1ebfp t\u1ea3i tr\u1ecdng c\u1ee7a n\u00f3 v\u00e0o b\u1ed9 nh\u1edb c\u1ee7a c\u00e1c quy tr\u00ecnh h\u1ee3p ph\u00e1p, ch\u1eb3ng h\u1ea1n nh\u01b0 explorer.exe, \u0111\u1ec3 tr\u00e1nh b\u1ecb ph\u00e1t hi\u1ec7n. K\u1ef9 thu\u1eadt n\u00e0y cho ph\u00e9p ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i ho\u1ea1t \u0111\u1ed9ng m\u00e0 kh\u00f4ng \u0111\u1ec3 l\u1ea1i b\u1ea5t k\u1ef3 d\u1ea5u v\u1ebft \u0111\u00e1ng ch\u00fa \u00fd n\u00e0o tr\u00ean \u1ed5 c\u1ee9ng, khi\u1ebfn vi\u1ec7c x\u00e1c \u0111\u1ecbnh v\u00e0 lo\u1ea1i b\u1ecf tr\u1edf n\u00ean kh\u00f3 kh\u0103n.<\/p>\n<h2>Ph\u00e2n t\u00edch c\u00e1c t\u00ednh n\u0103ng ch\u00ednh c\u1ee7a Poweliks.<\/h2>\n<p>Poweliks s\u1edf h\u1eefu m\u1ed9t s\u1ed1 t\u00ednh n\u0103ng ch\u00ednh khi\u1ebfn n\u00f3 tr\u1edf th\u00e0nh m\u1ed1i \u0111e d\u1ecda ti\u1ec1m t\u00e0ng:<\/p>\n<ol>\n<li>\n<p><strong>Th\u1ef1c thi kh\u00f4ng c\u1ea7n t\u1ec7p<\/strong>: L\u00e0 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i kh\u00f4ng d\u00f9ng t\u1ec7p, Poweliks kh\u00f4ng d\u1ef1a v\u00e0o c\u00e1c t\u1ec7p th\u1ef1c thi truy\u1ec1n th\u1ed1ng, g\u00e2y kh\u00f3 kh\u0103n cho vi\u1ec7c ph\u00e1t hi\u1ec7n b\u1eb1ng c\u00e1c gi\u1ea3i ph\u00e1p ch\u1ed1ng vi-r\u00fat d\u1ef1a tr\u00ean ch\u1eef k\u00fd truy\u1ec1n th\u1ed1ng.<\/p>\n<\/li>\n<li>\n<p><strong>S\u1ef1 ki\u00ean tr\u00ec l\u00e9n l\u00fat<\/strong>: B\u1eb1ng c\u00e1ch nh\u00fang ch\u00ednh n\u00f3 v\u00e0o c\u00e1c kh\u00f3a \u0111\u0103ng k\u00fd quan tr\u1ecdng c\u1ee7a Windows, Poweliks \u0111\u1ea3m b\u1ea3o r\u1eb1ng n\u00f3 v\u1eabn t\u1ed3n t\u1ea1i trong su\u1ed1t qu\u00e1 tr\u00ecnh kh\u1edfi \u0111\u1ed9ng l\u1ea1i h\u1ec7 th\u1ed1ng, \u0111\u1ea3m b\u1ea3o ho\u1ea1t \u0111\u1ed9ng li\u00ean t\u1ee5c v\u00e0 c\u00e1c c\u01a1 h\u1ed9i \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u.<\/p>\n<\/li>\n<li>\n<p><strong>Ti\u00eam b\u1ed9 nh\u1edb<\/strong>: Ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i ti\u00eam m\u00e3 \u0111\u1ed9c v\u00e0o c\u00e1c quy tr\u00ecnh h\u1ee3p ph\u00e1p, che gi\u1ea5u s\u1ef1 hi\u1ec7n di\u1ec7n c\u1ee7a n\u00f3 trong b\u1ed9 nh\u1edb c\u1ee7a h\u1ec7 th\u1ed1ng.<\/p>\n<\/li>\n<li>\n<p><strong>K\u1ef9 thu\u1eadt n\u00e9 tr\u00e1nh<\/strong>: Poweliks \u0111\u01b0\u1ee3c trang b\u1ecb c\u00e1c c\u01a1 ch\u1ebf ch\u1ed1ng ph\u00e2n t\u00edch v\u00e0 tr\u1ed1n tr\u00e1nh, khi\u1ebfn c\u00e1c nh\u00e0 nghi\u00ean c\u1ee9u b\u1ea3o m\u1eadt g\u1eb7p kh\u00f3 kh\u0103n trong vi\u1ec7c nghi\u00ean c\u1ee9u h\u00e0nh vi c\u1ee7a n\u00f3 v\u00e0 ph\u00e1t tri\u1ec3n c\u00e1c bi\u1ec7n ph\u00e1p \u0111\u1ed1i ph\u00f3.<\/p>\n<\/li>\n<\/ol>\n<h2>Vi\u1ebft nh\u1eefng lo\u1ea1i Poweliks t\u1ed3n t\u1ea1i. S\u1eed d\u1ee5ng b\u1ea3ng v\u00e0 danh s\u00e1ch \u0111\u1ec3 vi\u1ebft.<\/h2>\n<p>C\u00f3 m\u1ed9t s\u1ed1 bi\u1ebfn th\u1ec3 v\u00e0 phi\u00ean b\u1ea3n c\u1ee7a Poweliks, m\u1ed7i bi\u1ebfn th\u1ec3 c\u00f3 nh\u1eefng \u0111\u1eb7c \u0111i\u1ec3m v\u00e0 kh\u1ea3 n\u0103ng ri\u00eang. M\u1ed9t s\u1ed1 lo\u1ea1i Powerik \u0111\u00e1ng ch\u00fa \u00fd bao g\u1ed3m:<\/p>\n<table>\n<thead>\n<tr>\n<th>Lo\u1ea1i Powerik<\/th>\n<th>S\u1ef1 mi\u00eau t\u1ea3<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Poweliks.A<\/td>\n<td>Bi\u1ebfn th\u1ec3 ban \u0111\u1ea7u \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n v\u00e0o n\u0103m 2014.<\/td>\n<\/tr>\n<tr>\n<td>Poweriks.B<\/td>\n<td>M\u1ed9t phi\u00ean b\u1ea3n c\u1eadp nh\u1eadt v\u1edbi c\u00e1c k\u1ef9 thu\u1eadt tr\u1ed1n tr\u00e1nh n\u00e2ng cao.<\/td>\n<\/tr>\n<tr>\n<td>Poweliks.C<\/td>\n<td>M\u1ed9t bi\u1ebfn th\u1ec3 ph\u1ee9c t\u1ea1p h\u01a1n v\u1edbi kh\u1ea3 n\u0103ng \u0111a h\u00ecnh, khi\u1ebfn kh\u00f3 b\u1ecb ph\u00e1t hi\u1ec7n h\u01a1n.<\/td>\n<\/tr>\n<tr>\n<td>Poweliks.D<\/td>\n<td>T\u1eadp trung v\u00e0o ch\u1ee9c n\u0103ng l\u1ecdc d\u1eef li\u1ec7u v\u00e0 ghi nh\u1eadt k\u00fd b\u00e0n ph\u00edm.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>C\u00e1ch s\u1eed d\u1ee5ng Poweliks, c\u00e1c v\u1ea5n \u0111\u1ec1 v\u00e0 gi\u1ea3i ph\u00e1p li\u00ean quan \u0111\u1ebfn vi\u1ec7c s\u1eed d\u1ee5ng.<\/h2>\n<p>\u0110i\u1ec1u c\u1ea7n thi\u1ebft l\u00e0 ph\u1ea3i l\u00e0m r\u00f5 r\u1eb1ng Poweliks l\u00e0 m\u1ed9t ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i v\u00e0 vi\u1ec7c s\u1eed d\u1ee5ng ph\u1ea7n m\u1ec1m n\u00e0y ho\u00e0n to\u00e0n d\u00e0nh cho c\u00e1c ho\u1ea1t \u0111\u1ed9ng b\u1ea5t h\u1ee3p ph\u00e1p v\u00e0 phi \u0111\u1ea1o \u0111\u1ee9c, ch\u1eb3ng h\u1ea1n nh\u01b0 \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u, gian l\u1eadn t\u00e0i ch\u00ednh v\u00e0 khai th\u00e1c h\u1ec7 th\u1ed1ng. Vi\u1ec7c s\u1eed d\u1ee5ng ph\u1ea7n m\u1ec1m h\u1ee3p ph\u00e1p v\u00e0 c\u00f3 \u0111\u1ea1o \u0111\u1ee9c kh\u00f4ng bao gi\u1edd \u0111\u01b0\u1ee3c li\u00ean quan \u0111\u1ebfn Poweliks ho\u1eb7c b\u1ea5t k\u1ef3 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i n\u00e0o kh\u00e1c.<\/p>\n<p>\u0110\u1ed1i v\u1edbi ng\u01b0\u1eddi d\u00f9ng v\u00e0 t\u1ed5 ch\u1ee9c \u0111ang \u0111\u1ed1i m\u1eb7t v\u1edbi m\u1ed1i \u0111e d\u1ecda t\u1eeb Poweliks, vi\u1ec7c \u00e1p d\u1ee5ng c\u00e1c bi\u1ec7n ph\u00e1p b\u1ea3o m\u1eadt ch\u1ee7 \u0111\u1ed9ng l\u00e0 r\u1ea5t quan tr\u1ecdng. M\u1ed9t s\u1ed1 ph\u01b0\u01a1ng ph\u00e1p hay nh\u1ea5t \u0111\u1ec3 b\u1ea3o v\u1ec7 kh\u1ecfi Poweliks v\u00e0 c\u00e1c m\u1ed1i \u0111e d\u1ecda t\u01b0\u01a1ng t\u1ef1 bao g\u1ed3m:<\/p>\n<ol>\n<li>\n<p><strong>C\u1eadp nh\u1eadt th\u01b0\u1eddng xuy\u00ean<\/strong>: Lu\u00f4n c\u1eadp nh\u1eadt h\u1ec7 \u0111i\u1ec1u h\u00e0nh v\u00e0 ph\u1ea7n m\u1ec1m gi\u00fap v\u00e1 c\u00e1c l\u1ed7 h\u1ed5ng \u0111\u00e3 bi\u1ebft m\u00e0 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i c\u00f3 th\u1ec3 khai th\u00e1c.<\/p>\n<\/li>\n<li>\n<p><strong>Ch\u1ed1ng virus v\u00e0 ch\u1ed1ng ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i<\/strong>: Vi\u1ec7c tri\u1ec3n khai c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt \u0111\u00e1ng tin c\u1eady bao g\u1ed3m t\u00ednh n\u0103ng ph\u00e1t hi\u1ec7n d\u1ef1a tr\u00ean h\u00e0nh vi c\u00f3 th\u1ec3 gi\u00fap x\u00e1c \u0111\u1ecbnh v\u00e0 gi\u1ea3m thi\u1ec3u ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i kh\u00f4ng d\u00f9ng t\u1ec7p nh\u01b0 Poweliks.<\/p>\n<\/li>\n<li>\n<p><strong>Gi\u00e1o d\u1ee5c nh\u00e2n vi\u00ean<\/strong>: Gi\u00e1o d\u1ee5c nh\u00e2n vi\u00ean v\u1ec1 k\u1ef9 thu\u1eadt l\u1eeba \u0111\u1ea3o v\u00e0 th\u1ef1c h\u00e0nh duy\u1ec7t web an to\u00e0n c\u00f3 th\u1ec3 ng\u0103n ch\u1eb7n c\u00e1c vect\u01a1 l\u00e2y nhi\u1ec5m ban \u0111\u1ea7u.<\/p>\n<\/li>\n<li>\n<p><strong>Ph\u00e2n \u0111o\u1ea1n m\u1ea1ng<\/strong>: Vi\u1ec7c tri\u1ec3n khai ph\u00e2n \u0111o\u1ea1n m\u1ea1ng c\u00f3 th\u1ec3 gi\u00fap ng\u0103n ch\u1eb7n s\u1ef1 l\u00e2y nhi\u1ec5m ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i v\u00e0 h\u1ea1n ch\u1ebf chuy\u1ec3n \u0111\u1ed9ng ngang trong m\u1ea1ng.<\/p>\n<\/li>\n<\/ol>\n<h2>C\u00e1c \u0111\u1eb7c \u0111i\u1ec3m ch\u00ednh v\u00e0 c\u00e1c so s\u00e1nh kh\u00e1c v\u1edbi c\u00e1c thu\u1eadt ng\u1eef t\u01b0\u01a1ng t\u1ef1 d\u01b0\u1edbi d\u1ea1ng b\u1ea3ng v\u00e0 danh s\u00e1ch.<\/h2>\n<p>D\u01b0\u1edbi \u0111\u00e2y l\u00e0 so s\u00e1nh gi\u1eefa Poweliks v\u00e0 ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i d\u1ef1a tr\u00ean t\u1ec7p truy\u1ec1n th\u1ed1ng:<\/p>\n<table>\n<thead>\n<tr>\n<th>\u0110\u1eb7c tr\u01b0ng<\/th>\n<th>Poweliks (Ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i kh\u00f4ng c\u00f3 t\u1ec7p)<\/th>\n<th>Ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i d\u1ef1a tr\u00ean t\u1ec7p truy\u1ec1n th\u1ed1ng<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Ki\u00ean tr\u00ec<\/td>\n<td>D\u1ef1a tr\u00ean s\u1ed5 \u0111\u0103ng k\u00fd, th\u01b0\u1eddng tr\u00fa trong b\u1ed9 nh\u1edb<\/td>\n<td>D\u1ef1a tr\u00ean t\u1ec7p, th\u1ef1c thi tr\u00ean \u0111\u0129a<\/td>\n<\/tr>\n<tr>\n<td>Ph\u00e1t hi\u1ec7n<\/td>\n<td>Tr\u1ed1n tr\u00e1nh AV d\u1ef1a tr\u00ean ch\u1eef k\u00fd truy\u1ec1n th\u1ed1ng<\/td>\n<td>C\u00f3 th\u1ec3 ph\u00e1t hi\u1ec7n \u0111\u01b0\u1ee3c b\u1eb1ng AV d\u1ef1a tr\u00ean ch\u1eef k\u00fd<\/td>\n<\/tr>\n<tr>\n<td>G\u1ee1 b\u1ecf<\/td>\n<td>Kh\u00f3 kh\u0103n v\u00ec thi\u1ebfu h\u1ed3 s\u01a1<\/td>\n<td>D\u1ec5 d\u00e0ng h\u01a1n v\u1edbi d\u1ea5u v\u1ebft d\u1ef1a tr\u00ean t\u1eadp tin<\/td>\n<\/tr>\n<tr>\n<td>Ph\u00e2n b\u1ed5<\/td>\n<td>T\u1ec7p \u0111\u00ednh k\u00e8m email, trang web b\u1ecb nhi\u1ec5m virus<\/td>\n<td>T\u1ea3i xu\u1ed1ng, ph\u01b0\u01a1ng ti\u1ec7n b\u1ecb nhi\u1ec5m, v.v.<\/td>\n<\/tr>\n<tr>\n<td>T\u00e1c \u0111\u1ed9ng l\u00e2y nhi\u1ec5m<\/td>\n<td>Ti\u00eam b\u1ed9 nh\u1edb, ho\u1ea1t \u0111\u1ed9ng l\u00e9n l\u00fat<\/td>\n<td>Nhi\u1ec5m t\u1eadp tin, t\u1eadp tin hi\u1ec3n th\u1ecb<\/td>\n<\/tr>\n<tr>\n<td>\u0110\u1ed9 ph\u1ee9c t\u1ea1p ph\u00e2n t\u00edch<\/td>\n<td>Kh\u00f3 kh\u0103n do ho\u1ea1t \u0111\u1ed9ng d\u1ef1a tr\u00ean tr\u00ed nh\u1edb<\/td>\n<td>D\u1ec5 d\u00e0ng h\u01a1n v\u1edbi c\u00e1c m\u1eabu t\u1ec7p<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Quan \u0111i\u1ec3m v\u00e0 c\u00f4ng ngh\u1ec7 c\u1ee7a t\u01b0\u01a1ng lai li\u00ean quan \u0111\u1ebfn Poweliks.<\/h2>\n<p>T\u01b0\u01a1ng lai c\u1ee7a ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i, bao g\u1ed3m c\u1ea3 Poweliks, d\u1ef1 ki\u1ebfn s\u1ebd c\u00f2n c\u00f3 s\u1ef1 tinh vi h\u01a1n n\u1eefa trong c\u00e1c k\u1ef9 thu\u1eadt l\u1ea9n tr\u00e1nh v\u00e0 s\u1eed d\u1ee5ng c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng do AI \u0111i\u1ec1u khi\u1ec3n. Nh\u1eefng ng\u01b0\u1eddi t\u1ea1o ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i c\u00f3 th\u1ec3 s\u1eed d\u1ee5ng c\u00e1c ph\u01b0\u01a1ng ph\u00e1p n\u00e2ng cao \u0111\u1ec3 tr\u00e1nh b\u1ecb ph\u00e1t hi\u1ec7n v\u00e0 l\u00e2y nhi\u1ec5m c\u00e1c m\u1ee5c ti\u00eau hi\u1ec7u qu\u1ea3 h\u01a1n. Vi\u1ec7c ph\u00e1t tri\u1ec3n c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt t\u1eadp trung v\u00e0o ph\u00e1t hi\u1ec7n d\u1ef1a tr\u00ean h\u00e0nh vi v\u00e0 th\u00f4ng tin t\u00ecnh b\u00e1o v\u1ec1 m\u1ed1i \u0111e d\u1ecda theo th\u1eddi gian th\u1ef1c s\u1ebd tr\u1edf n\u00ean quan tr\u1ecdng trong vi\u1ec7c ch\u1ed1ng l\u1ea1i c\u00e1c m\u1ed1i \u0111e d\u1ecda \u0111ang gia t\u0103ng n\u00e0y.<\/p>\n<h2>C\u00e1ch s\u1eed d\u1ee5ng ho\u1eb7c li\u00ean k\u1ebft m\u00e1y ch\u1ee7 proxy v\u1edbi Poweliks.<\/h2>\n<p>M\u00e1y ch\u1ee7 proxy c\u00f3 th\u1ec3 b\u1ecb l\u1ea1m d\u1ee5ng khi k\u1ebft h\u1ee3p v\u1edbi Poweliks \u0111\u1ec3 che gi\u1ea5u ho\u1ea1t \u0111\u1ed9ng li\u00ean l\u1ea1c c\u1ee7a ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i v\u1edbi m\u00e1y ch\u1ee7 ra l\u1ec7nh v\u00e0 ki\u1ec3m so\u00e1t (C&amp;C). B\u1eb1ng c\u00e1ch \u0111\u1ecbnh tuy\u1ebfn l\u01b0u l\u01b0\u1ee3ng truy c\u1eadp th\u00f4ng qua c\u00e1c m\u00e1y ch\u1ee7 proxy, t\u1ed9i ph\u1ea1m m\u1ea1ng c\u00f3 th\u1ec3 l\u00e0m x\u00e1o tr\u1ed9n ngu\u1ed3n li\u00ean l\u1ea1c v\u00e0 khi\u1ebfn vi\u1ec7c truy t\u00ecm l\u1ea1i h\u1ec7 th\u1ed1ng b\u1ecb nhi\u1ec5m tr\u1edf n\u00ean kh\u00f3 kh\u0103n h\u01a1n. Tuy nhi\u00ean, \u0111i\u1ec1u quan tr\u1ecdng c\u1ea7n nh\u1ea5n m\u1ea1nh l\u00e0 c\u00e1c nh\u00e0 cung c\u1ea5p m\u00e1y ch\u1ee7 proxy h\u1ee3p ph\u00e1p, nh\u01b0 OneProxy, tu\u00e2n th\u1ee7 c\u00e1c ch\u00ednh s\u00e1ch nghi\u00eam ng\u1eb7t ch\u1ed1ng l\u1ea1i vi\u1ec7c t\u1ea1o \u0111i\u1ec1u ki\u1ec7n cho c\u00e1c ho\u1ea1t \u0111\u1ed9ng b\u1ea5t h\u1ee3p ph\u00e1p v\u00e0 \u0111\u1ea3m b\u1ea3o d\u1ecbch v\u1ee5 c\u1ee7a h\u1ecd \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng m\u1ed9t c\u00e1ch c\u00f3 tr\u00e1ch nhi\u1ec7m.<\/p>\n<h2>Li\u00ean k\u1ebft li\u00ean quan<\/h2>\n<p>\u0110\u1ec3 bi\u1ebft th\u00eam th\u00f4ng tin v\u1ec1 Poweliks v\u00e0 c\u00e1c ph\u01b0\u01a1ng ph\u00e1p hay nh\u1ea5t v\u1ec1 an ninh m\u1ea1ng, h\u00e3y tham kh\u1ea3o c\u00e1c t\u00e0i nguy\u00ean sau:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Trojan%3AWin32%2FPoweliks\" target=\"_new\" rel=\"noopener nofollow\">B\u00e1o c\u00e1o th\u00f4ng tin b\u1ea3o m\u1eadt c\u1ee7a Microsoft<\/a> b\u1edfi Trung t\u00e2m th\u00f4ng tin v\u1ec1 m\u1ed1i \u0111e d\u1ecda c\u1ee7a Microsoft<\/li>\n<li><a href=\"https:\/\/us-cert.cisa.gov\/ncas\/alerts\/TA17-117A\" target=\"_new\" rel=\"noopener nofollow\">C\u1ea3nh b\u00e1o US-CERT<\/a> tr\u00ean Hidden Cobra \u2013 C\u00f4ng c\u1ee5 truy c\u1eadp t\u1eeb xa c\u1ee7a Tri\u1ec1u Ti\u00ean: FALLCHILL<\/li>\n<li><a href=\"https:\/\/www.sans.org\/security-awareness-training\/resources\/file\/poweliks-fileless-malware\" target=\"_new\" rel=\"noopener nofollow\">Vi\u1ec7n SANS<\/a> t\u00e0i nguy\u00ean v\u1ec1 Ph\u1ea7n m\u1ec1m \u0111\u1ed9c h\u1ea1i kh\u00f4ng c\u00f3 t\u1ec7p Poweliks<\/li>\n<\/ul>","protected":false},"featured_media":478487,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-478486","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Poweliks: A Comprehensive Overview<\/mark>","faq_items":[{"question":"What is Poweliks?","answer":"<p>Poweliks is a type of fileless malware that resides in the Windows registry, making it difficult to detect and remove. Unlike traditional malware, Poweliks does not rely on files and instead operates solely in memory, making it stealthy and evasive.<\/p>"},{"question":"How did Poweliks originate?","answer":"<p>The exact origins of Poweliks are unclear, but it was first discovered in 2014 by security experts at Microsoft. It is believed to have been created by sophisticated cybercriminals aiming to exploit the stealth capabilities of fileless malware.<\/p>"},{"question":"How does Poweliks work?","answer":"<p>Poweliks embeds itself into critical Windows registry keys, such as \"Shell\" or \"Userinit,\" ensuring persistence across system reboots. It then injects its malicious code into legitimate processes, hiding its presence in the system's memory. This fileless execution technique evades traditional antivirus and anti-malware solutions.<\/p>"},{"question":"What are the key features of Poweliks?","answer":"<p>The key features of Poweliks include fileless execution, stealthy persistence through the registry, memory injection, and advanced evasion techniques. These characteristics make it a potent threat and difficult to detect or remove.<\/p>"},{"question":"What types of Poweliks exist?","answer":"<p>There are several variants of Poweliks, each with unique capabilities. Some notable types include Poweliks.A (the original variant), Poweliks.B (with enhanced evasion techniques), Poweliks.C (with polymorphic capabilities), and Poweliks.D (focused on data exfiltration and keylogging).<\/p>"},{"question":"Can Poweliks be detected and removed?","answer":"<p>Poweliks is notoriously difficult to detect and remove due to its fileless nature. Traditional signature-based antivirus solutions may struggle to identify it. However, employing behavior-based detection and regular security updates can help mitigate the risk.<\/p>"},{"question":"How is Poweliks distributed?","answer":"<p>Poweliks is typically distributed through malicious email attachments, infected websites, or exploit kits. Users should exercise caution when interacting with suspicious emails or websites to avoid infection.<\/p>"},{"question":"What are the potential consequences of Poweliks infection?","answer":"<p>Once infected, Poweliks can engage in various malicious activities, including data theft, keylogging, and downloading additional harmful payloads onto the system.<\/p>"},{"question":"How can I protect my computer from Poweliks?","answer":"<p>To protect your computer from Poweliks and similar threats, follow these best practices:<\/p><ol><li>Keep your operating system and software up-to-date to patch known vulnerabilities.<\/li><li>Use reliable antivirus and anti-malware software with behavior-based detection capabilities.<\/li><li>Educate yourself and your employees about phishing techniques and safe browsing practices.<\/li><li>Implement network segmentation to contain infections and limit their spread.<\/li><\/ol>"},{"question":"Can proxy servers be linked to Poweliks?","answer":"<p>Proxy servers can potentially be misused by cybercriminals to conceal Poweliks' communication with command-and-control servers. However, legitimate proxy server providers, like OneProxy, have strict policies against supporting illegal activities and promote responsible use of their services.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki\/478486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/wiki\/478486\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/media\/478487"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/vn\/wp-json\/wp\/v2\/media?parent=478486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}