Техническая информация
- <SYSTEM32>\tasks\runtimebroker
- %APPDATA%\microsoft\windows\system32\runtimebrokerhost.exe
- %APPDATA%\microsoft\windows\security\sysruntimemonitor.exe
- nul
- 'ip##pi.com':80
- 'xm#####.nanopool.org':10343
- 'xm#####.nanopool.org':10300
- http://ip##pi.com/json/
- 'xm#####.nanopool.org':10343
- 'xm#####.nanopool.org':10300
- DNS ASK ip##pi.com
- DNS ASK xm#####.nanopool.org
- '%APPDATA%\microsoft\windows\security\sysruntimemonitor.exe'
- '%APPDATA%\microsoft\windows\system32\runtimebrokerhost.exe' --internal-supervised Local\RuntimeBrokerHost-heartbeat-4100-1781818973448 Local\RuntimeBrokerHost-heartbeat-4100-1781818973448 4100 %APPDATA%\Microsoft\Windows\Security\SysRuntimeMonitor.exe
- '<SYSTEM32>\schtasks.exe' /Create /F /SC ONLOGON /TN RuntimeBroker /TR \"%APPDATA%\Microsoft\Windows\Security\SysRuntimeMonitor.exe\"