Technical Information
- %WINDIR%\syswow64\svchost.exe
- 'cu###########094.cos.ap-nanjing.myqcloud.com':443
- '12#.#20.200.241':8088
- 'cu###########094.cos.ap-nanjing.myqcloud.com':443
- '12#.#20.200.241':8088
- DNS ASK cu###########094.cos.ap-nanjing.myqcloud.com
- '%WINDIR%\syswow64\svchost.exe' -360' (with hidden window)
- '%WINDIR%\syswow64\svchost.exe' -360