Technical Information
- %WINDIR%\explorer.exe
- 'de######tesfrancaises.com':80
- 'xt###ower.xyz':80
- 'no###uis.cat':80
- 'ha###marche.com':80
- '20###606.com':80
- DNS ASK de######tesfrancaises.com
- DNS ASK xt###ower.xyz
- DNS ASK no###uis.cat
- DNS ASK ve###lit.net
- DNS ASK ha###marche.com
- DNS ASK 20###606.com
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"