Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run] 'ADSL Dial' = '<Full path to file>'
- [<HKLM>\SYSTEM\ControlSet001\Services\SA3282] 'ImagePath' = '%TEMP%\VE2jaao.sys'
- NtCreateThread, handler: unknown
- NtProtectVirtualMemory, handler: unknown
- %TEMP%\VE2jaao.sys
- <Current directory>\VMwarec.exe
- <Current directory>\VMware.exe
- <Current directory>\smss.bat
- <Full path to file>
- %TEMP%\VE2jaao.sys
- <Current directory>\VMware.exe
- <Current directory>\smss.bat
- <Current directory>\VMwarec.exe
- %TEMP%\VE2jaao.sys
- '12#.#25.114.144':80
- 'mi##.ppxxmr.com':3333
- http://www.ba##u.com/ via 12#.#25.114.144
- DNS ASK www.ba##u.com
- DNS ASK mi##.ppxxmr.com
- '<Current directory>\VMwarec.exe'
- '<Current directory>\VMware.exe' -a cryptonight -o stratum+tcp://111.111.111.1:3333 -u 44UGwLdFrLBU67GoR4VmWXCX9U56hnX6mPMJrtBefhZZHZgFRSKN6fJFu4ow4PUsqRe4eAjqhsaay9vi36ozaCct6ZxWCSG+001 -p x --donate-level=1
- '<SYSTEM32>\cmd.exe' /c ""<Current directory>\smss.bat" "