Trojan.DNSChanger circumvents Powershell restrictions | Malwarebytes Labs
Common Information
Type Value
UUID a129f463-03fe-43fc-8338-d4c87a468516
Fingerprint d48c83722d1af79a
Analysis status DONE
Considered CTI value 0
Text language
Published Jan. 22, 2016, midnight
Added to db Jan. 18, 2023, 8:33 p.m.
Last updated Nov. 18, 2024, 1:38 a.m.
Headline Trojan.DNSChanger circumvents Powershell restrictions
Title Trojan.DNSChanger circumvents Powershell restrictions | Malwarebytes Labs
Detected Hints/Tags/Attributes 19/1/5
Attributes
Details Type #Events CTI Value
Details File 1209
powershell.exe
Details IPv4 1
82.163.142.3
Details IPv4 1
95.211.158.130
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces