Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\Com04Hd\Parameters] 'ServiceDll' = '%APPDATA%\67msam.dll'
- [<HKLM>\SYSTEM\ControlSet001\Services\Com04Hd] 'ImagePath' = '<SYSTEM32>\svchost.exe -k "Com04Hd"'
- [<HKLM>\SYSTEM\ControlSet001\Services\Com04Hd] 'Start' = '00000002'
- %APPDATA%\wuacul8.exe
- <SYSTEM32>\svchost.ini
- %APPDATA%\67msam.dll
- <Full path to file>
- 'po##.####troneum.hashvault.pro':80
- 'rj.#c1.me':1881
- DNS ASK po##.####troneum.hashvault.pro
- DNS ASK rj.#c1.me
- '%APPDATA%\wuacul8.exe' -o stratum+tcp://pool.electroneum.hashvault.pro:80 -u etnk4xgG8sxdzzTYVi8D9m9YDXYM9HS1R4Tj6UXnqfGeEpdFawi7f6AXo7XuCCAS5oBsLFAPPtYKA3TJyWCqTdUM2geUjs9xJy -p good:188388@qq.com
- '<SYSTEM32>\svchost.exe' -k "Com04Hd"