Examples of Mal/Behav-262 include:
Example 1
Runtime Analysis
Copies Itself To
- C:\WINDOWS\system32\wininet.exe
Dropped Files
- C:\WINDOWS\system32\svshost.dll
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
- SysRun
- {D7FFD784-5276-42D1-887B-00267870A4C7}
- HKCR\CLSID\{D7FFD784-5276-42D1-887B-00267870A4C7}\InProcServer32
- (Default)
- C:\WINDOWS\system32\svshost.dll
Example 2
Runtime Analysis
Copies Itself To
- C:\WINDOWS\system32\wininet.exe
Dropped Files
- C:\WINDOWS\system32\svshost.dll
Registry Keys Created
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
- SysRun
- {D7FFD784-5276-42D1-887B-00267870A4C7}
- HKCR\CLSID\{D7FFD784-5276-42D1-887B-00267870A4C7}\InProcServer32
- (Default)
- C:\WINDOWS\system32\svshost.dll