Technical Information
- %WINDIR%\syswow64\explorer.exe
- %LOCALAPPDATA%\microsoft\temporary.dat
- 'ip###ger.org':443
- 'cd#.##scordapp.com':443
- 'oc##.thawte.com':80
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- 'ip###ger.org':443
- 'cd#.##scordapp.com':443
- DNS ASK ip###ger.org
- DNS ASK cd#.##scordapp.com
- DNS ASK microsoft.com
- DNS ASK oc##.thawte.com
- '%WINDIR%\syswow64\explorer.exe'