Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\login data1
- nul
- 'ws####3sdfer.com':80
- http://www.ws####3sdfer.com/index.php/api/a
- http://www.ws####3sdfer.com/index.php/api/fb
- DNS ASK ws####3sdfer.com
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' 1.1.1.1 -n 1 -w 3000