Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegHost' = '%APPDATA%\Microsoft\RegHost.exe'
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\WinRing0x64.sys
- %WINDIR%\explorer.exe
- %APPDATA%\microsoft\reghost.exe
- %APPDATA%\microsoft\regmodule.exe
- %APPDATA%\microsoft\onedrive.exe
- %APPDATA%\microsoft\regdata.exe
- '18#.#37.234.33':8080
- 'po##.#ashvault.pro':3333
- http://18#.##7.234.33:8080/hs via 18#.#37.234.33
- http://18#.##7.234.33:8080/pm via 18#.#37.234.33
- http://18#.##7.234.33:8080/xr via 18#.#37.234.33
- http://18#.##7.234.33:8080/wd via 18#.#37.234.33
- 'po##.#ashvault.pro':3333
- DNS ASK po##.#ashvault.pro
- '%WINDIR%\bfsvc.exe' -log 0 -nvdo 1 -pool etc.2miners.com:1010 -wal 0x6A7B383b4c9eDA1348cc1fD31FDefcC6f20C05f5 -coin etc -worker bigdickzxc -cclock +500 -cvddc +500
- '%WINDIR%\notepad.exe' --coin=XMR -o pool.hashvault.pro:3333 -u 46FNsHGMqoXQJuHTpekQ4s3T1t8auRdCr5FK5TbP7kAHNRPxWm6icZEi8p64mE7wNady1fzY8TzZ5PrwfBEso4TNP1LpvVw -p bigdickzxc
- '%WINDIR%\explorer.exe' "123qWef0" "" "None" "etc"