Technical Information
- <SYSTEM32>\dwmcompat.dll
- <SYSTEM32>\glew32.dll
- <SYSTEM32>\mr_jean.vbs
- <SYSTEM32>\windivert.dll
- <SYSTEM32>\windivert64.sys
- <SYSTEM32>\libcurl.dll
- 'ke##uth.win':443
- '80.##0.113.62':80
- 'x1.#.lencr.org':80
- 'e7.#.lencr.org':80
- 'pu##########178f47b0bfb30cc4a7eb122c.r2.dev':443
- http://e7.#.lencr.org/112.crl
- 'ke##uth.win':443
- 'pu##########86274d9db7a2e74b84a1a3e3.r2.dev':443
- DNS ASK ke##uth.win
- DNS ASK x1.#.lencr.org
- DNS ASK e7.#.lencr.org
- DNS ASK pu##########178f47b0bfb30cc4a7eb122c.r2.dev
- DNS ASK pu##########86274d9db7a2e74b84a1a3e3.r2.dev
- '<SYSTEM32>\cmd.exe' /c mode con: lines=12 cols=35
- '<SYSTEM32>\mode.com' con: lines=12 cols=35