Technical Information
- %CommonProgramFiles%\services\trustedinsteller.exe
- %CommonProgramFiles%\services\trustedinsteller.exe
- <Full path to file>
- from <Full path to file> to <Current directory>\[ffd8e105b3f589a15f9a15c540165081]
- 'po##.#sa-138.com':80
- DNS ASK po##.#sa-138.com
- '%CommonProgramFiles%\services\trustedinsteller.exe' -a cryptonight -o stratum+tcp://pool.usa-138.com:80 -u 4B7yFmYw2qvEtWZDDnZVeY16HHpwTtuYBg6EMn5xdDbM3ggSEnQFDWDHH6cqdEYaPx4iQvAwLNu8NLc21QxDU84GGxZEY7S -p x
- '%CommonProgramFiles%\services\trustedinsteller.exe' -a cryptonight -o stratum+tcp://pool.usa-138.com:80 -u 4B7yFmYw2qvEtWZDDnZVeY16HHpwTtuYBg6EMn5xdDbM3ggSEnQFDWDHH6cqdEYaPx4iQvAwLNu8NLc21QxDU84GGxZEY7S -p x' (with hidden window)