Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Cyif' = '"%TEMP%\Ewew\cyif.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\91cba54dec2c7b8e] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\91cba54dec2c7b8e] 'ImagePath' = '<DRIVERS>\91cba54dec2c7b8e.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\2f60e] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- '%TEMP%\Ewew\cyif.exe'
- <SYSTEM32>\ctfmon.exe
- NtOpenThread, драйвер-обработчик: 91cba54dec2c7b8e.sys
- NtOpenProcess, драйвер-обработчик: 91cba54dec2c7b8e.sys
- <DRIVERS>\91cba54dec2c7b8e.sys
- %APPDATA%\ceyj.uzs
- %TEMP%\Ewew\cyif.exe
- <DRIVERS>\2f60e.sys
- <DRIVERS>\2f60e.sys
- '10#.#53.212.95':4808
- '20#.#05.112.231':2718
- '23.##.64.182':7013
- '13#.#1.18.14':2202
- ClassName: 'Indicator' WindowName: '(null)'