Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'explorer' = '%APPDATA%\booster\xmrig.exe -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 4JUdGzvrMFDWrUUwY3toJATSeNwjn54LkCnKBPRzDuhzi5vSe...
- %TEMP%\c706.tmp.exe
- %APPDATA%\booster\manager.exe
- %APPDATA%\booster\xmrig.exe
- 'xm#####.nanopool.org':14444
- 'xm#####.nanopool.org':14444
- DNS ASK qt##cker.tk
- DNS ASK xm#####.nanopool.org
- '%APPDATA%\booster\xmrig.exe' -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 4JUdGzvrMFDWrUUwY3toJATSeNwjn54LkCnKBPRzDuhzi5vSepHfUckJNxRL2gjkNrSqtCoRUrEDAgRwsQvVCjZbRzL9pCSYqvM4EaC4kh/15 -p x --donate-level=1 -B -t 1