Technical Information
- <SYSTEM32>\mstsc.exe
- nul
- 'oy########ax7goo6aej.badedsho.fun':443
- 'ba########koo5ioqu8i.badedsho.site':443
- DNS ASK oy########ax7goo6aej.badedsho.fun
- DNS ASK ba########koo5ioqu8i.badedsho.site
- '<SYSTEM32>\mstsc.exe'
- '<SYSTEM32>\cmd.exe' /C timeout 120 > Nul & Del /f /q "<Full path to file>"
- '<SYSTEM32>\timeout.exe' 120