Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] 'Debugger' = '<SYSTEM32>\ctfmon_oi.exe'
- %WINDIR%\syswow64\ctfmon_oi.exe
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net