Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'ApplicationName' = '<Full path to file>'
- %TEMP%\xmr55.exe
- %TEMP%\config.json
- %TEMP%\winring0x64.sys
- %TEMP%\sha256sums
- 'cd#.##scordapp.com':443
- 'gu##.##neroocean.stream':10128
- 'cd#.##scordapp.com':443
- 'gu##.##neroocean.stream':10128
- DNS ASK cd#.##scordapp.com
- DNS ASK gu##.##neroocean.stream
- '%TEMP%\xmr55.exe'
- '%TEMP%\xmr55.exe' ' (with hidden window)