Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %TEMP%\WinRing0x64.sys
- %TEMP%\dilhost.exe
- %TEMP%\0chqr40c.bat
- nul
- %TEMP%\dilhost.exe
- 'xm#.##inrarigs.com':3333
- 'xm#.##inrarigs.com':3333
- DNS ASK xm#.##inrarigs.com
- '%TEMP%\dilhost.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\0CHQR40C.bat" "<Full path to file>" "
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\tasklist.exe' /fi "IMAGENAME eq dIlhost.exe"
- '<SYSTEM32>\find.exe' /i "dIlhost.exe"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\0CHQR40C.bat" "<Full path to file>" "' (with hidden window)