Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ZcbQd' = '<Full path to file>'
- [<HKLM>\SYSTEM\ControlSet001\Services\hy5.5] 'ImagePath' = '%TEMP%\wea5tlK.sys'
- '<Current directory>\win1ogon.exe' -o pool.minexmr.com:7777 -u 41tUtBDRmz6CqzzTSq5AeHNLjmTtVsVDxAjYaP4YebvBZyotAS3h6X8ffiq5fdmLPxaEAm64TqgbVbtRy6dsi16V29xioi7 --max-cpu-usage 75 --print-time 10
- NtOpenProcess, handler: wea5tlK.sys
- <Current directory>\win1ogon.exe
- %TEMP%\wea5tlK.sys
- <Current directory>\ProcessExtended.dll
- <Full path to file>
- <Current directory>\win1ogon.exe
- <Current directory>\ProcessExtended.dll
- %TEMP%\wea5tlK.sys
- %TEMP%\wea5tlK.sys
- 'po##.#inexmr.com':7777
- DNS ASK po##.#inexmr.com