Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%' -Force -ErrorAction SilentlyContinue"
- <SYSTEM32>\cmd.exe
- %TEMP%\th77fa.tmp
- 'po####n.drpc.org':443
- '92.##9.164.93':8080
- 'xm##ool.eu':5555
- http://92.###.164.93:8080/api/updates/current via 92.##9.164.93
- http://92.###.164.93:8080/api/miners/submit via 92.##9.164.93
- 'po####n.drpc.org':443
- 'xm##ool.eu':5555
- DNS ASK po####n.drpc.org
- DNS ASK xm##ool.eu
- '<SYSTEM32>\cmd.exe' --encargs 585e011d1b121117581f0004101f4542555e0a520d1e17021a1c095c10065f47404650525806454a413b203a3e4a3c381f1528251d00271834343425331a0613393f1f031e1a0b0111173d39312a543406455c38203f5343212a0a4...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath '%LOCALAPPDATA%' -Force -ErrorAction SilentlyContinue" (со скрытым окном)