Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %TEMP%\WinRing0x64.sys
- %TEMP%\content\5572-5584-<File name>.exe-15-42-53-376.dump
- %TEMP%\driver.sys
- %TEMP%\winring0x64.sys
- %TEMP%\randomfile_1.vbs
- %TEMP%\randomfile_1.vbe
- %TEMP%\randomfile_2.vbs
- %TEMP%\randomfile_2.vbe
- %TEMP%\randomfile_3.vbs
- %TEMP%\randomfile_3.vbe
- 'ap#.##legram.org':443
- 'xm#.##yptex.network':7777
- '15#.#01.129.91':443
- 'ap#.##legram.org':443
- 'xm#.##yptex.network':7777
- DNS ASK ap#.##legram.org
- DNS ASK xm#.##yptex.network
- '%TEMP%\driver.sys' --http-enabled=false --autosave --randomx-mode=auto --randomx-rdmsr --randomx-wrmsr --randomx-numa --randomx-scratchpad-prefetch-mode=1 --cpu --cpu-huge-pages --cpu-yield --cpu-asm --cpu-rx=0,2...