Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%TEMP%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %TEMP%\WinRing0x64.sys
- %TEMP%\dilhost.exe
- %TEMP%\4tp92u5g.bat
- nul
- %TEMP%\dilhost.exe
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'xm#.##inrarigs.com':3333
- 'xm#.##inrarigs.com':3333
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK xm#.##inrarigs.com
- '%TEMP%\dilhost.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\4TP92U5G.bat" "<Full path to file>" "
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\tasklist.exe' /fi "IMAGENAME eq dIlhost.exe"
- '<SYSTEM32>\find.exe' /i "dIlhost.exe"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\4TP92U5G.bat" "<Full path to file>" "' (with hidden window)