Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '<SYSTEM32>\WindowsPowerShell\v1.0\test\WinRing0x64.sys'
- 'WinRing0_1_2_0' <SYSTEM32>\WindowsPowerShell\v1.0\test\WinRing0x64.sys
- <SYSTEM32>\windowspowershell\v1.0\test\config.json
- <SYSTEM32>\windowspowershell\v1.0\test\xmrig.exe
- 'do####.v2.xmrig.com':3333
- 'do####.v2.xmrig.com':3333
- DNS ASK do####.v2.xmrig.com
- ClassName: 'EDIT' WindowName: ''
- '<SYSTEM32>\windowspowershell\v1.0\test\xmrig.exe'