Техническая информация
- <SYSTEM32>\tasks\runtime broker
- %WINDIR%\explorer.exe
- %APPDATA%\runtime broker\runtime broker
- %TEMP%\winring0x64.sys
- 'pa###bin.com':443
- '12#.#5.231.32':80
- 'ht##bin.org':80
- http://ht##bin.org/ip
- 'pa###bin.com':443
- DNS ASK pa###bin.com
- DNS ASK ht##bin.org
- '%APPDATA%\runtime broker\runtime broker'
- '<SYSTEM32>\cmd.exe' cmd /c powershell -EncodedCommand "PAAjADgAMABkADYANgA5AGMAYwBlAGYAOQA4ADQAZgA2ADkAOQBjADkAMgA0AGUAYQA4ADgAOABiADcAYQBhAGEAYgAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjADQAOABhAG... (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand "PAAjADgAMABkADYANgA5AGMAYwBlAGYAOQA4ADQAZgA2ADkAOQBjADkAMgA0AGUAYQA4ADgAOABiADcAYQBhAGEAYgAjAD4AIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAAPAAjADQAOABhAGYAOAA1AGMAMgBlAGIA...
- '<SYSTEM32>\schtasks.exe' /create /sc minute /mo 1 /tn "Runtime Broker" /rl HIGHEST /tr "%APPDATA%\Runtime Broker\Runtime Broker"
- '%WINDIR%\explorer.exe' --donate-level 0 --cpu-max-threads-hint 30 -o pool.hashvault.pro:80 -u 42LYsSTjkZR6qxBkYScoFAHVE9MkTeXT2bda7wvc16aZ1MKEqaoKydrb1LWwjGdSvkFbTRzSuFCdg2o37k43warJ6cnhid2.x (со скрытым окном)