Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'FireEyeTest' = '%APPDATA%\FireEyeTest.exe'
- '%TEMP%\testexploit.exe'
- %TEMP%\testexploit.exe
- %APPDATA%\fireeyetest.exe
- %TEMP%\testexploit.exe
- '%APPDATA%\fireeyetest.exe' "%TEMP%\TestExploit.exe"