Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'crsass' = '<SYSTEM32>\crsas.exe'
- [<HKLM>\SOFTWARE\Microsoft\Active Setup\Installed Components\{8C444546-5345-8688-1D61-57E0613967AB}] 'StubPath' = '<SYSTEM32>\crsas.exe'
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\crsas.exe
- 'ba####08.no-ip.biz':3460
- 'localhost':3460
- DNS ASK ba####08.no-ip.biz