Chapter 1:
// date = 2020.12.14
//surmise, Ordinal 

https://s3-us-west-2.amazonaws.com/secure.notion-static.com/dcb95343-43f3-4e6b-a445-f84a9a4f0e1c/Untitled.png

Host-Based Signatures: These indicators often identify files created or modified by

the malware or specific changes that it makes to the registry.

Network signatures: detect malicious code by monitoring network traffic

https://s3-us-west-2.amazonaws.com/secure.notion-static.com/6896afd8-016e-43e9-baa0-7a1ddf6d6a21/Untitled.png

Analysis: use GDI32.dll and User32.dll most likely have a GUI interface. Also is able to manipulate the process/files. Using Advapi32.dll which indicates it does something with the registries. such as. \Software\Microsoft\Windows\CurrentVersion\Run, which is a registry key that controls which programs are automatically run when booting.