Technical Information
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'st#######ppy-ewe.ngrok-free.app':443
- DNS ASK st#######ppy-ewe.ngrok-free.app
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "%APPDATA%\System64"
- '<SYSTEM32>\cmd.exe' /c icacls "%APPDATA%\System64" /deny Everyone:(OI)(CI)F
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\System64"
- '<SYSTEM32>\icacls.exe' "%APPDATA%\System64" /deny Everyone:(OI)(CI)F
- '<SYSTEM32>\cmd.exe' /c attrib +s +h "%APPDATA%\System64"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c icacls "%APPDATA%\System64" /deny Everyone:(OI)(CI)F' (with hidden window)