Technical Information
- %WINDIR%\explorer.exe
- explorer.exe process, Amsi.dll module
- 'ra#.####ubusercontent.com':443
- '12#.#5.231.32':80
- 'x1.#.lencr.org':80
- 'r1#.#.lencr.org':80
- http://r1#.#.lencr.org/91.crl
- 'ra#.####ubusercontent.com':443
- DNS ASK ra#.####ubusercontent.com
- DNS ASK x1.#.lencr.org
- DNS ASK r1#.#.lencr.org