Technical Information
- <SYSTEM32>\dwm.exe
- 'o3######.sched.sma.tdnsv5.com':80
- 'cd#.#utaopt.cn':80
- 'k8###.#8shangcheng.com':80
- http://dd####kd.mmakd.ren/api/userconfig/uc_336311a016184326ddbdd61edd4eeb52.json
- http://dd####kd.mmakd.ren/API/General/thenewseven
- http://k8###.#8shangcheng.com/api/userconfig/uc_336311a016184326ddbdd61edd4eeb52.json
- http://dd####kd.mmakd.ren/API/General/arearst
- DNS ASK cd#.#ackow.com
- DNS ASK dd####kd.mmakd.ren
- DNS ASK cd#.#####w.com.cdn.dnsv1.com
- DNS ASK 21######.sched.sma.tdnsstic1.cn
- DNS ASK o3######.sched.sma.tdnsv5.com
- DNS ASK cd#.#utaopt.cn
- DNS ASK 5c##########d7691e2e1d926a4a2e7b.gazigz.cn
- DNS ASK 58.###mon.gazigz.cn
- DNS ASK k8###.#8shangcheng.com
- ClassName: 'ProgMan' WindowName: ''
- ClassName: 'SHELLDLL_DefView' WindowName: ''
- ClassName: 'SysListView32' WindowName: ''
- '<SYSTEM32>\ipconfig.exe' /flushdns' (with hidden window)
- '<SYSTEM32>\ipconfig.exe' /flushdns