Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Security Server' = '<Full path to file>'
- '%APPDATA%\MicroMon\curl.exe' -o pool.minexmr.com:4444 -u 4BrL51JCc9NGQ71kWhnYoDRffsDZy7m1HUU7MRU4nUMXAHNFBEJhkTZV9HdaL4gfuNBxLPc3BeMkLGaPbF5vWtANQqTt52ygNEM1YivU8a -p x -cpu-affinity 75
- '%APPDATA%\MicroMon\curl.exe' (downloaded from the Internet)
- %APPDATA%\MicroMon\curl.exe
- '13#.#04.171.132':80
- 'wp#d':80
- http://13#.#04.171.132/monero/updmr.php
- http://13#.#04.171.132/monero/updbt.php
- http://13#.#04.171.132/monero/gate.php?ma########################################################################################################################################################...
- http://11#.#11.111.1/wpad.dat via wp#d
- http://13#.#04.171.132/monero/mr/curl.exe
- DNS ASK wp#d