Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'aaa' = 'C:\Users\Public\regsvr32.exe'
- %WINDIR%\syswow64\svchost.exe
- from <Full path to file> to C:\users\public\<File name>.dll
- '43.##2.163.147':800
- '%WINDIR%\syswow64\svchost.exe' ' (with hidden window)
- '%WINDIR%\syswow64\svchost.exe'