Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<Full path to file>' = '<Full path to file>:*:Enabled:ldrsoft'
- '22#.#12.36.51':80
- '%WINDIR%\syswow64\cmd.exe' /c <Full path to file>00.bat
- '%WINDIR%\syswow64\cmd.exe' /c <Full path to file>00.bat' (with hidden window)