Technical Information
- %ALLUSERSPROFILE%\shell.ini
- 'pi#.##ixiongz.com':443
- 'st#####.##gitalcertvalidation.com':80
- 'microsoft.com':80
- 'oc##.thawte.com':80
- 'pi#.##ixiongz.com':443
- DNS ASK pi#.##ixiongz.com
- DNS ASK st#####.##gitalcertvalidation.com
- DNS ASK microsoft.com
- DNS ASK oc##.thawte.com
- '%WINDIR%\syswow64\cmd.exe' /c del /q "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del /q "<Full path to file>"