Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'RustCrypter' = 'C:/Rust Crypter - INFECTED MACHINE/<File name>.exe'
- C:\rust crypter - infected machine\<File name>.exe
- C:\rust crypter - infected machine\<File name>.exe
- 'po##.#upportxmr.com':443
- 'mo#####.map.fastly.net':443
- DNS ASK po##.#upportxmr.com
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '<SYSTEM32>\attrib.exe' +h "C:/Rust Crypter - INFECTED MACHINE"
- '<SYSTEM32>\attrib.exe' +h "C:/Rust Crypter - INFECTED MACHINE\<File name>.exe"