Technical Information
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\Google\Libs\WR64.sys'
- 'WinRing0_1_2_0' %APPDATA%\Google\Libs\WR64.sys
- %WINDIR%\explorer.exe
- %APPDATA%\google\libs\wr64.sys
- 'xm#.#miners.com':12222
- 'co####signs2.com':443
- 'xm#.#miners.com':12222
- DNS ASK xm#.#miners.com
- DNS ASK co####signs2.com
- '%WINDIR%\explorer.exe' gnwtibxemfwjte1 6E3sjfZq2rJQaxvLPmXgsA4f0StS9pic9Xw++oZ1mnbMNdSoXP4ts/KtNDhUPQkUOWlLosYbrY2pwtQQU1JTuikNmZuGmV+6BbKlyKFD6zdAaaNcQqky2iJHSWRIHnss9X/nab3QoNVM/Ta0kPMjvUxJH02YjP5XrdviLouahJX3Q1zD8...