Техническая информация
- %TEMP%\s2ao.0
- %TEMP%\s2ao.1
- %TEMP%\s2ao.2
- %TEMP%\smd.mnth
- %TEMP%\s2ao.0
- %TEMP%\s2ao.1
- %TEMP%\s2ao.2
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- '10#.#87.146.29':80
- 'ge####tetoken.my.id':80
- 'ge####tetoken.my.id':443
- http://10#.#87.146.29/check/status.php
- http://10#.#87.146.29/samarinda/FileKey.mentah
- http://ge####tetoken.my.id/samarinda/Api/status1.php?e=######################################
- 'ge####tetoken.my.id':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK ge####tetoken.my.id
- '%WINDIR%\syswow64\cmd.exe' /c wmic bios get serialnumber >> %TEMP%\s2ao.0
- '%WINDIR%\syswow64\wbem\wmic.exe' bios get serialnumber
- '%WINDIR%\syswow64\cmd.exe' /c wmic cpu get processorid >> %TEMP%\s2ao.1
- '%WINDIR%\syswow64\wbem\wmic.exe' cpu get processorid
- '%WINDIR%\syswow64\cmd.exe' /c wmic diskdrive get serialnumber >> %TEMP%\s2ao.2
- '%WINDIR%\syswow64\wbem\wmic.exe' diskdrive get serialnumber
- '%WINDIR%\syswow64\cmd.exe' /c color A