Technical Information
- [<HKLM>\Software\Microsoft\Windows\CurrentVersion\Run] 'HDNA' = '%PROGRAMDATA%\inttemp\csrss.exe'
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\user.exe
- %PROGRAMDATA%\inttemp\csrss.exe
- %PROGRAMDATA%\inttemp\temp\user6-26-2020.1n0d
- %PROGRAMDATA%\inttemp\csrss.exe
- <Drive name for removable media>:\user.exe
- <Drive name for removable media>:\autorun.inf
- DNS ASK dc####.zapto.org
- '%PROGRAMDATA%\inttemp\csrss.exe'