Technical Information
- [HKLM\software\Wow6432Node\microsoft\windows nt\currentversion\winlogon] 'userinit' = 'userinit.exe,<SYSTEM32>\ntos.exe,'
- %WINDIR%\syswow64\ntos.exe
- '34.##9.100.209':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- '34.##9.100.209':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net