Technical Information
- %WINDIR%\5lvd.exe
- %TEMP%\content\2308-980-5lvd.exe-10-00-03-321.dump
- from %WINDIR%\5lvd.exe to %TEMP%\928156\....\temporaryfile
- '96##zhu.com':443
- 'x1.#.lencr.org':80
- '80.##0.113.62':80
- http://x1.#.lencr.org/
- '96##zhu.com':443
- DNS ASK 96##zhu.com
- DNS ASK x1.#.lencr.org
- '%WINDIR%\5lvd.exe'