Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'powerremot' = '%WINDIR%\powerremot.exe'
- %WINDIR%\syswow64\sc.exe
- %WINDIR%\syswow64\net.exe
- %WINDIR%\powerremot.exe
- %WINDIR%\temp\svcsosc.exe
- %WINDIR%\powerremot.exe в %TEMP%\[264c61541abcf0bc6256deeb819989aa]
- %WINDIR%\powerremot.exe в %TEMP%\[fd77cc1095b04492f9cdec6f197b41f0]
- %WINDIR%\powerremot.exe
- %TEMP%\[fd77cc1095b04492f9cdec6f197b41f0]
- 'mo###ohash.com':5555
- DNS ASK mo###ohash.com
- '%WINDIR%\powerremot.exe'
- '%WINDIR%\temp\svcsosc.exe' -a cryptonight -o monerohash.com:5555 -u 43PBziBqWRUaZNyQP7VQ2qReHVQUci6df58Gg5JJGMZsCtnanLu5nJBhA1ucAj6GqgT1DsJ49AxmG59vRdMv1Vvw6SgB2rq -p x -k --donate-level=1
- '%WINDIR%\temp\svcsosc.exe' -a cryptonight -o monerohash.com:5555 -u 43PBziBqWRUaZNyQP7VQ2qReHVQUci6df58Gg5JJGMZsCtnanLu5nJBhA1ucAj6GqgT1DsJ49AxmG59vRdMv1Vvw6SgB2rq -p x -k --donate-level=1' (со скрытым окном)