diff --git a/Additional Analysis/RUYK/2020-10-27/Analysis.md b/Additional Analysis/RUYK/2020-10-27/Analysis.md index 56901ae..b598732 100644 --- a/Additional Analysis/RUYK/2020-10-27/Analysis.md +++ b/Additional Analysis/RUYK/2020-10-27/Analysis.md @@ -277,7 +277,7 @@ return; ``` // Example of dropped files on the disk %temp%\PaRyHBUIXlan.exe -%temp%\PaRyHBUIXlan.exe +%temp%\pBbowloYglan.exe %temp%\nXsTetgJilan.exe // Pattern -> %temp%\\[a-zA-Z]{9}lan.exe