Masot is a backdoor, which provides the attacker with unauthorized remote access to the compromised computer. The intruder can take screenshots of user activity, terminate running processes, download arbitrary files and thus steal user sensitive information. Masot can disable the Windows Firewall. The backdoor runs a hidden web server and can be controlled through the web interface. The attacker can reconfigure the parasite.
explorer64.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunexplorer64