Technical Information
- <SYSTEM32>\dllhost.exe
- firefox.exe
- msedge.exe
- dllhost.exe process, ntdll.dll module
- 't.#e':443
- 'se####vernous.com':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'se####vernous.com':443
- DNS ASK t.#e
- DNS ASK se####vernous.com
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\dllhost.exe'
- '%ProgramFiles%\mozilla firefox\firefox.exe' --headless --incognito
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --headless --disable-gpu