Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegHost' = '%APPDATA%\Microsoft\RegHost.exe'
- %WINDIR%\explorer.exe
- %APPDATA%\microsoft\reghost.exe
- %APPDATA%\microsoft\regmodule.exe
- %APPDATA%\microsoft\onedrive.exe
- %APPDATA%\microsoft\regdata.exe
- '18#.#37.234.33':8080
- http://18#.##7.234.33:8080/hs via 18#.#37.234.33
- http://18#.##7.234.33:8080/lm via 18#.#37.234.33
- http://18#.##7.234.33:8080/xr via 18#.#37.234.33
- http://18#.##7.234.33:8080/wd via 18#.#37.234.33
- '%WINDIR%\bfsvc.exe' -a TON --pool wss://eu1.stratum.ton-pool.com/stratum --user UQAJaSCanxuy1UsMNoup11rbV4WBezOefthHUI6sa5GWxzM4
- '%WINDIR%\explorer.exe' "??" "" "?????" "ton" 1