Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Driver' = '%APPDATA%\Sysfiles\<File name>.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\driver.url
- %APPDATA%\sysfiles\driver.exe
- from <Full path to file> to %APPDATA%\sysfiles\<File name>.exe
- 'ip###ger.org':443
- 'ip###ger.org':443
- DNS ASK ip###ger.org
- '%APPDATA%\sysfiles\driver.exe' -o xmr.2miners.com:2222 -u 49jFPe6oHr7RnUidP9Vg4TN755DrUEU6jRpk1QcEStD7XtbTZ13YSeaMAHUaN2wwYf3p2pDLCpjgyDexbPSNHWnWPMs24PJ -p x -k -v=0 --donate-level=1 -t 0
- '%APPDATA%\sysfiles\driver.exe' -o xmr.2miners.com:2222 -u 49jFPe6oHr7RnUidP9Vg4TN755DrUEU6jRpk1QcEStD7XtbTZ13YSeaMAHUaN2wwYf3p2pDLCpjgyDexbPSNHWnWPMs24PJ -p x -k -v=0 --donate-level=1 -t 0' (with hidden window)