Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Host Process Windows Services' = '%APPDATA%\svchost\svchost.exe'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '0' = '"%APPDATA%\svchost\m\svchost.exe" -a yescrypt -p x -o stratum+tcp://hub.miningpoolhub.com:17021 -u my9.test'
- %APPDATA%\svchost\svchost.exe
- %TEMP%\248566a2d5dd4dc2908930b2479958ab.bat
- nul
- DNS ASK google.com
- '%APPDATA%\svchost\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\248566a2d5dd4dc2908930b2479958ab.bat" "
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\ping.exe' -n 10 localhost
- '<SYSTEM32>\ping.exe' -n 30 localhost
- '<SYSTEM32>\schtasks.exe' /create /tn "Host Process Windows Services" /sc ON 'LogON /tr "%APPDATA%\svchost\svchost.exe" /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\248566a2d5dd4dc2908930b2479958ab.bat" "' (with hidden window)