Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\xmrig.lnk
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%APPDATA%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %APPDATA%\WinRing0x64.sys
- %APPDATA%\safecore.exe
- nul
- <SYSTEM32>\windowspowershell\v1.0\xmrig.log
- 'gu##.##neroocean.stream':10001
- 'gu##.##neroocean.stream':10001
- '15#.#01.1.91':443
- DNS ASK gu##.##neroocean.stream
- '%APPDATA%\safecore.exe'
- '<SYSTEM32>\cmd.exe' /C timeout /t 2 >NUL & del /f /q "<Full path to file>"
- '<SYSTEM32>\timeout.exe' /t 2
- '%APPDATA%\safecore.exe' ' (with hidden window)