Technical Information
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '<Current directory>\WinRing0x64.sys'
- 'WinRing0_1_2_0' <Current directory>\WinRing0x64.sys
- <Current directory>\syslib.dll
- <Current directory>\version.txt
- <Current directory>\config.json
- <Current directory>\systemmanagement.exe
- http://mr##tp.xyz/sql/syslib.dll
- DNS ASK vi###soft.ir
- DNS ASK mr##tp.xyz
- DNS ASK mr##ool.xyz
- '<Current directory>\systemmanagement.exe'