Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '5cb3ebcf8fa94002265a0641e8fcc95d' = '"%TEMP%\csrrcs.exe" ..'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '5cb3ebcf8fa94002265a0641e8fcc95d' = '"%TEMP%\csrrcs.exe" ..'
- %HOMEPATH%\Start Menu\Programs\Startup\5cb3ebcf8fa94002265a0641e8fcc95d.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\csrrcs.exe' = '%TEMP%\csrrcs.exe:*:Enabled:csrrcs.exe'
- '%TEMP%\csrrcs.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\csrrcs.exe" "csrrcs.exe" ENABLE
- %TEMP%\csrrcs.exe
- 'ri####345.hopto.org':1177
- DNS ASK ri####345.hopto.org