Technical Information
- <SYSTEM32>\rdpshell.exe
- %WINDIR%\windowsshell76423.log
- %WINDIR%\windowssystemupdate277.log
- '47.#8.35.46':36281
- DNS ASK wa###ngwan.site
- DNS ASK ec###9e1.site
- DNS ASK al###ncom.site
- DNS ASK al####store.site
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)