Technical Information
- <SYSTEM32>\mstsc.exe
- http://cr#.#ectigo.com/SectigoRSADomainValidationSecureServerCA.crt
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK cr#.#ectigo.com
- DNS ASK microsoft.com
- DNS ASK to##oy.com
- '<SYSTEM32>\mstsc.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c timeout 3 && del <Full path to file>' (with hidden window)
- '<SYSTEM32>\mstsc.exe'
- '<SYSTEM32>\ctfmon.exe'
- '<SYSTEM32>\cmd.exe' /c timeout 3 && del <Full path to file>
- '<SYSTEM32>\timeout.exe' 3