Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'WinAFen' = '<Full path to file>'
- '%WINDIR%\Minings.exe' -u 49Vt621p2WEL5gfchixrs6ZxnoB7jWkLVKAmYY6VBXV6SP9QBoKQvpfGqscovwcMVNanvGjDq423U9x6GEcRkDgWMhtT45U -p x
- %WINDIR%\1496197270_log.txt
- %WINDIR%\Minings.exe
- %WINDIR%\pools.txt
- 'mo###ohash.com':5555
- DNS ASK mo###ohash.com