Trojan.DNSChanger circumvents Powershell restrictions | Malwarebytes Labs
Tags
Common Information
Type | Value |
---|---|
UUID | a129f463-03fe-43fc-8338-d4c87a468516 |
Fingerprint | d48c83722d1af79a |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Jan. 22, 2016, midnight |
Added to db | Jan. 18, 2023, 8:33 p.m. |
Last updated | Nov. 18, 2024, 1:38 a.m. |
Headline | Trojan.DNSChanger circumvents Powershell restrictions |
Title | Trojan.DNSChanger circumvents Powershell restrictions | Malwarebytes Labs |
Detected Hints/Tags/Attributes | 19/1/5 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | File | 1209 | powershell.exe |
|
Details | IPv4 | 1 | 82.163.142.3 |
|
Details | IPv4 | 1 | 95.211.158.130 |
|
Details | Windows Registry Key | 1 | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters |
|
Details | Windows Registry Key | 1 | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces |