Technical Information
- %WINDIR%\Tasks\xbooster.job
- '%WINDIR%\dshdhddh.exe' -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 4JUdGzvrMFDWrUUwY3toJATSeNwjn54LkCnKBPRzDuhzi5vSepHfUckJNxRL2gjkNrSqtCoRUrEDAgRwsQvVCjZbRwFRDTx2ydzMSdp6ZD/5 -p x
- '%WINDIR%\dshdhddh.exe' (downloaded from the Internet)
- %WINDIR%\dshdhddh.exe
- 'xt###ker.club':80
- 's3######st-2.amazonaws.com':80
- 'localhost':1038
- http://xt###ker.club/click.php?cn###############
- http://s3######st-2.amazonaws.com/zminer/NsCpuCNMiner32.exe
- DNS ASK xt###ker.club
- DNS ASK s3######st-2.amazonaws.com