Technical Information
- '' (downloaded from the Internet)
- %TEMP%\aliwssv.exe
- <Full path to file>
- '22#.#86.3.73':8591
- 'yu###.xueliwu.com':80
- http://yu###.xueliwu.com/rcr/107.exe
- DNS ASK yu###.xueliwu.com
- '%TEMP%\aliwssv.exe'
- '<SYSTEM32>\cmd.exe' /c del "<Full path to file>"