Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\WsysSvc] 'ImagePath' = '%ALLUSERSPROFILE%\Application Data\eSafe\<File name>.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\WsysSvc] 'Start' = '00000002'
- '%ALLUSERSPROFILE%\Application Data\eSafe\<File name>.exe'
- '%ALLUSERSPROFILE%\Application Data\eSafe\<File name>.exe' -run
- %ALLUSERSPROFILE%\Application Data\eSafe\log\<File name>.LOG
- %ALLUSERSPROFILE%\Application Data\eSafe\<File name>.exe
- 'xa.###gcloud.com':80
- http://xa.###gcloud.com/v4/sof-newgdp/XXwareXXirtualXIDEXHardXDrive_11000000000000000001?ac###################################################################################################
- DNS ASK xa.###gcloud.com