Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Windows Update' = '"<LS_APPDATA>\HuIokmGHYU\crss.exe"'
- dllhost.exe
- <SYSTEM32>\svchost.exe
- <LS_APPDATA>\HuIokmGHYU\crss.exe
- %TEMP%\dllhost.exe
- '%TEMP%\dllhost.exe'
- '<SYSTEM32>\svchost.exe' -a cryptonight -o stratum+tcp://xmr.pool.minergate.com:45560 -u systemupdates@protonmail.ch -p x -t 2
- '<SYSTEM32>\cmd.exe'