Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Ulef' = '"%TEMP%\Ofzuor\ulef.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\a399fefefdfa7796] 'Start' = '00000000'
- [<HKLM>\SYSTEM\ControlSet001\Services\a399fefefdfa7796] 'ImagePath' = '<DRIVERS>\a399fefefdfa7796.sys'
- [<HKLM>\SYSTEM\ControlSet001\Services\27e2f] 'Start' = '00000001'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- '%TEMP%\Ofzuor\ulef.exe'
- <SYSTEM32>\cscript.exe
- NtOpenThread, драйвер-обработчик: a399fefefdfa7796.sys
- NtOpenProcess, драйвер-обработчик: a399fefefdfa7796.sys
- %APPDATA%\eqho.ifp
- %TEMP%\NPX73D4.bat
- <DRIVERS>\a399fefefdfa7796.sys
- %TEMP%\Ofzuor\ulef.exe
- <DRIVERS>\27e2f.sys
- <DRIVERS>\27e2f.sys
- '85.#00.41.9':8835
- '99.##.173.219':8302
- '61.#8.200.5':3397
- '10#.#4.30.223':6215
- '19#.#7.198.162':2096
- '17#.#45.217.122':2943
- '18#.159.2.2':4316
- '17#.#9.110.91':1442
- '17#.#6.157.26':6705
- '85.##.52.205':4199
- '11#.#00.233.38':3426
- '68.##7.193.98':2489
- ClassName: 'Indicator' WindowName: ''