Technical Information
- %TEMP%\x1ork3)]csud)$u9[tgn.tmp
- <Full path to file>
- from <Full path to file> to %TEMP%\[3fc58bb6970fe568c133d24adcef5541]
- 'ip##8.com':80
- 'ip##8.com':443
- http://www.ip##8.com/
- 'ip##8.com':443
- DNS ASK ip##8.com
- DNS ASK se#####.baigou51.com
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /c del "<Full path to file>"' (with hidden window)