Техническая информация
- [HKLM\System\CurrentControlSet\Services\vdkezf] 'ImagePath' = 'cmd.exe /c echo vdkezf > \\.\pipe\vdkezf'
- [HKLM\System\CurrentControlSet\Services\IvdWY] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\IvdWY] 'ImagePath' = '"%WINDIR%\TEMP\yciEBPnQ.exe" szRYDqa'
- [HKLM\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\Temp\WinRing0x64.sys'
- 'vdkezf' cmd.exe /c echo vdkezf > \\.\pipe\vdkezf
- 'IvdWY' "%WINDIR%\TEMP\yciEBPnQ.exe" szRYDqa
- 'WinRing0_1_2_0' %WINDIR%\Temp\WinRing0x64.sys
- <SYSTEM32>\services.exe
- <SYSTEM32>\cmd.exe
- %WINDIR%\temp\yciebpnq.exe
- %WINDIR%\temp\golang-updater.exe
- %WINDIR%\temp\winring0x64.sys
- %WINDIR%\temp\cert_key.pem
- %WINDIR%\temp\cert.pem
- %WINDIR%\temp\patchza-updatedsze234.txt
- %WINDIR%\temp\loginfer.log
- '45.##2.35.107':6594
- '45.##2.35.107':2013
- 'de.#####um.herominers.com':1231
- '45.##2.35.107':6594
- 'de.#####um.herominers.com':1231
- DNS ASK de.#####um.herominers.com
- '%WINDIR%\temp\yciebpnq.exe' MMctl
- '%WINDIR%\temp\yciebpnq.exe' szRYDqa
- '%WINDIR%\temp\yciebpnq.exe'
- '%WINDIR%\temp\golang-updater.exe'
- '<SYSTEM32>\cmd.exe' /c echo vdkezf > \\.\pipe\vdkezf
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\TEMP\yciEBPnQ.exe" MMctl (со скрытым окном)
- '%WINDIR%\temp\golang-updater.exe' (со скрытым окном)