Warning! Audit Deprecated
Information
DAIRY starts by copying cmd.exe to Updatasched.exe in the %TEMP% directory. It will then launch Updatasched.exe with its STDIN and STDOUT
pipes tied to the malware. Next, the malware provides itself network access. It reads the registry for the Internet Explorer proxy settings
and adds itself to the firewall list if it is in use on the local machine via adding to the registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List.
ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.42