Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'CryptMinerSvc' = '<Full path to file>'
- <SYSTEM32>\tasks\cryptminersvcupdate
- %APPDATA%\microsoft\windows\start menu\programs\startup\cryptminersvc.lnk
- jfzet.exe process, Amsi.dll module
- jfzet.exe process, ntdll.dll module
- '255.255.255.255':4444
- '<LOCALNET>.1.42':4444
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "CryptMinerSvcUpdate" /tr "<Full path to file>" /sc MINUTE /mo 5 /f
- '<SYSTEM32>\schtasks.exe' /create /tn "CryptMinerSvcUpdate" /tr "<Full path to file>" /sc MINUTE /mo 5 /f