-

   rss_drweb_about_virs

 - e-mail

 

 -

 LiveInternet.ru:
: 24.08.2009
: 606
: 0
: 0

:


, ?

, 24 2025 . 16:00 +

24 2025

, Monero. , , , BMP.

, , 2022 , Services.exe, .NET-, VBscript. , , . , ubr.txt, PowerShell, ps1 txt.

ubr.txt , , . SilentCryptoMiner , Monero.

, , , -.

, Zoom (ZoomE.exe ZoomX.exe) Windows (Service32.exe Service64.exe) . . , , , , .

#drweb

PowerShell- ubr.txt

getcert[.]net, m.txt . .

#drweb

m.txt,

, .

. , , , , . , .

#drweb

#drweb

( : Marek Piwnicki)

, , Amadey, PowerShell- Async.ps1, BMP imghippo.com. : Trojan.PackedNET.2429 , :

  • UAC ,
  • Windows Defender,
  • Windows,
  • \Microsoft\Windows\WindowsBackup\ 'User'.

#drweb

Async1.ps

, DNS TXT . BMP :

  • Cleaner.txt PowerShell-, ,

  • m.txt PowerShell-, m.bmp IV.bmp. SilentCryptoMiner ,

  • Net.txt , DNS TXT windowscdn[.]site buyclients[.]xyz. , raw.githack[.]com.

DNS TXT DNS , . , , , .

#drweb

. GitHub . , , .

#drweb

, ,

, , 2022 , 340 XMR. , 6 7,5 . , , , . 3,3 , 1 XMR 40 .

, , , . : , .

#drweb

SilentCryptoMiner

PowerShell.Starter.98

PowerShell.DownLoader.1640

Trojan.PackedNET.2429

VBS.DownLoader.2822

https://news.drweb.ru/show/?i=14976&lng=ru&c=9


: [1] []
 

:
: 

: ( )

:

  URL