Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Microsoft Regedit' = '%SYSTEMDRIVE%\Windows (x86)\PolicyDefinitions\en-US\regedit.exe�'
- 'po##.#ashvault.pro':443
- 'po##.#ashvault.pro':443
- DNS ASK po##.#ashvault.pro
- '<SYSTEM32>\cmd.exe' /c cls