Technical Information
- msedge.exe
- firefox.exe
- qovxo.exe process, ntdll.dll module
- %TEMP%\~tmpb7f3.dat
- %TEMP%\~tmp976f.dat
- %TEMP%\~tmp4cc1.dat
- %TEMP%\~tmp82b3.dat
- %TEMP%\~tmp82e6.dat
- %TEMP%\~tmpddc8.dat
- 't.#e':443
- 'se####vernous.com':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'se####vernous.com':443
- DNS ASK t.#e
- DNS ASK se####vernous.com
- DNS ASK x1.#.lencr.org
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --headless --incognito
- '%ProgramFiles%\mozilla firefox\firefox.exe' --headless --disable-gpu