Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] '$99<File name>.exe' = '%HOMEPATH%\Documents\$99<File name>.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- %HOMEPATH%\documents\$99<File name>.exe
- 'mo#####.map.fastly.net':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '<SYSTEM32>\cmd.exe' reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "$99<File name>.exe" /t REG_SZ /d "%HOMEPATH%\Documents\$99<File name>.exe" /f
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'
- '<SYSTEM32>\reg.exe' add "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "$99<File name>.exe" /t REG_SZ /d "%HOMEPATH%\Documents\$99<File name>.exe" /f