Техническая информация
- <SYSTEM32>\tasks\runtimebroker
- %APPDATA%\microsoft\windows\system32\runtimebrokerhost.exe
- %APPDATA%\microsoft\windows\security\sysruntimemonitor.exe
- nul
- DNS ASK ip##pi.com
- DNS ASK xm#####.nanopool.org
- '%APPDATA%\microsoft\windows\security\sysruntimemonitor.exe'
- '%APPDATA%\microsoft\windows\system32\runtimebrokerhost.exe' --internal-supervised Local\RuntimeBrokerHost-heartbeat-4144-1781202622789 Local\RuntimeBrokerHost-heartbeat-4144-1781202622806 4144 %APPDATA%\Microsoft\Windows\Security\SysRuntimeMonitor.exe
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN RuntimeBroker /TR \"%APPDATA%\Microsoft\Windows\Security\SysRuntimeMonitor.exe\"