Forum Discussion

bl1ngod's avatar
bl1ngod
Icon for Bronze I rankBronze I
23 days ago

Incident Response: Suspicious Email – Part 3

Hey all

I am stuck at the ImmersiveLab Incident Response: Suspicious Email – Part 3 - Q3.

"The malware persists through reboots. What is the registry key value’s name that results in the malware executing automatically?"

There is an entry on HKCU Run for the Administrator. Am I on the right track? No matter what I enter it does not accept it.

kr

1 Reply

  • nvm... for others having the same thing... go try harder.. it's another key. You'll find the right hint here https://www.infosecinstitute.com/resources/malware-analysis/common-malware-persistence-mechanisms/