Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'PhantomPersistence' = '%HOMEPATH%\Downloads\AVG.exe'
- <SYSTEM32>\notepad.exe
- '<SYSTEM32>\notepad.exe'
- '<SYSTEM32>\cmd.exe' /q /c "type shellcode process injection 101, heres something _D3ceptic0n5_Ex3cu74ble}"