mirror of
https://github.com/aljazceru/securedorg.github.io.git
synced 2026-01-10 17:54:20 +01:00
finishing dynamic
This commit is contained in:
@@ -67,6 +67,7 @@ RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run\dope
|
||||
### Behavior & Control Flow
|
||||
|
||||
Processes Created dope.exe
|
||||
|
||||
1) Starts by decoding xor strings
|
||||
|
||||
2) Checks to see if dope.exe already exists in %APPDATA%
|
||||
|
||||
Reference in New Issue
Block a user