Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegHost' = '%APPDATA%\Microsoft\RegHost.exe'
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\WinRing0x64.sys
- %WINDIR%\explorer.exe
- %APPDATA%\microsoft\reghost.exe
- %APPDATA%\microsoft\regmodule.exe
- %APPDATA%\microsoft\onedrive.exe
- %APPDATA%\microsoft\regdata.exe
- '18#.#37.234.33':8080
- 'xm#.#miners.com':2222
- http://18#.##7.234.33:8080/hs via 18#.#37.234.33
- http://18#.##7.234.33:8080/lm via 18#.#37.234.33
- http://18#.##7.234.33:8080/xr via 18#.#37.234.33
- http://18#.##7.234.33:8080/wd via 18#.#37.234.33
- 'xm#.#miners.com':2222
- DNS ASK xm#.#miners.com
- '%WINDIR%\bfsvc.exe' --algo ETCHASH --pool eu1-etc.ethermine.org:4444 --user 0x8C40cd0F96391e6afc8F91744843EFc210e6B95d --worker dad --dualmode TONDUAL --dualpool wss://eu1.stratum.ton-pool.com/stratum --dualuser E...
- '%WINDIR%\notepad.exe' --coin=XMR -o xmr.2miners.com:2222 -u 497qdSyfY8t9dYnAGTnk8UigUbUPL4MXTFAxobWPDZ5rReSiVNL22GEGt9ptgNbDbTe3qyj3oRq2LfEYbws8yGqnSjBWHR6 -p dad
- '%WINDIR%\explorer.exe' "None" "" "dad" "etc"