Technical Information
- chrome.exe
- ldjklk.exe process, WINMM.dll module
- %APPDATA%\thunderbird\profiles\gbmwccb6.default-release\cookies.sqlite-shm
- %APPDATA%\thunderbird\profiles\gbmwccb6.default-release\places.sqlite-shm
- 'ba###yemas.com':443
- 'x1.#.lencr.org':80
- 'ip##pi.com':80
- '2.##.62.140':4449
- http://x1.#.lencr.org/
- http://ip##pi.com/line/?fi################
- 'ba###yemas.com':443
- '2.##.62.140':4449
- DNS ASK ba###yemas.com
- DNS ASK x1.#.lencr.org
- DNS ASK ip##pi.com
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --headless --disable-gpu --no-first-run --noerrdialogs --no-sandbox
- '%LOCALAPPDATA%\google\chrome\application\chrome.exe' --headless=new --load-extension="%TEMP%\rext_3132_1033031" --disable-extensions-except="%TEMP%\rext_3132_1033031" --no-first-run --no-default-browser-check --profile-directory="Default" --windo...' (with hidden window)