Technical Information
- %WINDIR%\Tasks\xbooster.job
- '%WINDIR%\hvvdfdsb.exe' -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 4judgzvrmfdwruuwy3tojatsenwjn54lkcnkbprzduhzi5vsephfuckjnxrl2gjknrsqtcoruredagrwsqvvcjzbrwhkbk2uwrj8snedxv/4 -p x
- '%WINDIR%\hvvdfdsb.exe' (downloaded from the Internet)
- %WINDIR%\hvvdfdsb.exe
- 'xt###ker.club':80
- 's3######st-2.amazonaws.com':80
- 'localhost':1036
- http://xt###ker.club/click.php?cn###################
- http://s3######st-2.amazonaws.com/zminer/NsCpuCNMiner32.exe
- DNS ASK xt###ker.club
- DNS ASK s3######st-2.amazonaws.com