Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '18.exe' = '%APPDATA%Microsoft\System\Services\18.exe'
- <SYSTEM32>\svchost.exe
- msconfig.exe
- %APPDATA%Microsoft\System\Services\18.exe
- %ProgramFiles%\msconfig.exe
- 'po##.#inexmr.com':5555
- DNS ASK po##.#inexmr.com
- '%ProgramFiles%\msconfig.exe'
- '<Full path to file>'
- '<SYSTEM32>\svchost.exe' -o pool.minexmr.com:5555 -u 47JFnFpMmLcWpbmcigV7FDYNjJsRDwohwN7mjrToekoj9q5Z9Xu9z1u1qK7nvYF23aFA52juAii9UVJ7vytPoKBEBzienc2 -p x -v 0 -t 2