Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run\] 'Windows Config' = '%HOMEPATH%\sysfrodolv.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%HOMEPATH%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %HOMEPATH%\WinRing0x64.sys
- %HOMEPATH%\sysmgnrsv.exe
- %HOMEPATH%\sysfrodolv.exe
- %HOMEPATH%\sysmgnrsv.exe
- %HOMEPATH%\sysfrodolv.exe
- '17#.#6.54.109':80
- '17#.#6.54.109':6060
- http://17#.#6.54.109/xmrig.exe
- '17#.#6.54.109':6060
- '%HOMEPATH%\sysmgnrsv.exe'
- '%HOMEPATH%\sysfrodolv.exe'
- '%HOMEPATH%\sysmgnrsv.exe' -o 17#.#6.54.109:6060 -u 83h9mBvy1LL2qW6c2HeWczYVJQsFDF7RfVqDnaiSfFBdDcxfyJfWhRnZqZkY5chb5b6tmKZ1PPhuQbNgXggCdwTrMYWN8hi -p x -t 1
- '%WINDIR%\syswow64\cmd.exe' /c %HOMEPATH%\sysmgnrsv.exe -o 17#.#6.54.109:6060 -u 83h9mBvy1LL2qW6c2HeWczYVJQsFDF7RfVqDnaiSfFBdDcxfyJfWhRnZqZkY5chb5b6tmKZ1PPhuQbNgXggCdwTrMYWN8hi -p x -t 1 (со скрытым окном)