From 7bef491864f97b24e8488a998ab2e218006c8743 Mon Sep 17 00:00:00 2001 From: Amanda Rousseau Date: Sun, 26 Mar 2017 23:34:06 -0700 Subject: [PATCH] finishing dynamic --- dynamic2.md | 1 + 1 file changed, 1 insertion(+) diff --git a/dynamic2.md b/dynamic2.md index ac74d0f..2ff4b01 100644 --- a/dynamic2.md +++ b/dynamic2.md @@ -67,6 +67,7 @@ RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run\dope ### Behavior & Control Flow Processes Created dope.exe + 1) Starts by decoding xor strings 2) Checks to see if dope.exe already exists in %APPDATA%