Forum Discussion
bl1ngod
Bronze I
23 days agoIncident Response: Suspicious Email – Part 3
Hey all
I am stuck at the ImmersiveLab Incident Response: Suspicious Email – Part 3 - Q3.
"The malware persists through reboots. What is the registry key value’s name that results in the malware executing automatically?"
There is an entry on HKCU Run for the Administrator. Am I on the right track? No matter what I enter it does not accept it.
kr
1 Reply
- bl1ngod
Bronze I
nvm... for others having the same thing... go try harder.. it's another key. You'll find the right hint here https://www.infosecinstitute.com/resources/malware-analysis/common-malware-persistence-mechanisms/