Technical Information
- 'C:\programdata\System32\Logs\svchost.exe'
- 'C:\programdata\WindowsTask\MicrosoftHost.exe' -a cryptonight -o stratum+tcp://xmr.pool.minergate.com:45560 -u stcubegames@gmail.com -p x -t 1
- 'C:\programdata\microsoft\intel\Cheat32.exe' /S
- '%TEMP%\RarSFX0\M.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\RarSFX0\R.vbs"
- '<SYSTEM32>\cmd.exe' /c C:\ProgramData\WindowsTask\MicrosoftHost.exe -a cryptonight -o stratum+tcp://xmr.pool.minergate.com:45560 -u stcubegames@gmail.com -p x -t 1
- '<SYSTEM32>\cmd.exe' /c ""c:\Programdata\Microsoft\Intel\OS.bat" "
- C:\programdata\microsoft\intel\OS.bat
- C:\programdata\WindowsTask\MicrosoftHost.exe
- C:\programdata\System32\Logs\svchost.exe
- C:\programdata\microsoft\intel\Cheat32.exe
- %TEMP%\RarSFX0\M.exe
- %TEMP%\RarSFX0\R.vbs
- C:\programdata\microsoft\intel\Cheat64.exe
- C:\programdata\System32\Logs\svchost.exe
- C:\programdata\WindowsTask\MicrosoftHost.exe
- %TEMP%\aut2.tmp
- %TEMP%\aut1.tmp
- 'xm#.###l.minergate.com':45560
- DNS ASK xm#.###l.minergate.com
- ClassName: 'EDIT' WindowName: ''