Technical Information
- %APPDATA%\thunderbird\profiles\rehh7ft5.default-release\cookies.sqlite-shm
- DNS ASK go###k.delivery
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "" "Get-WmiObject Win32_PortConnector"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "" "Get-WmiObject Win32_ComputerSystem"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "" "Get-WmiObject Win32_VideoController"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "" "Get-WmiObject Win32_PortConnector"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "" "Get-WmiObject Win32_ComputerSystem"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "" "Get-WmiObject Win32_VideoController"' (with hidden window)