Technical Information
- %TEMP%\904d.tmp
- %TEMP%\9815.tmp
- %TEMP%\97e5.tmp
- %TEMP%\97b5.tmp
- %TEMP%\9795.tmp
- %TEMP%\9765.tmp
- %TEMP%\9745.tmp
- %TEMP%\9705.tmp
- %TEMP%\96e5.tmp
- %TEMP%\96b5.tmp
- %TEMP%\9695.tmp
- %TEMP%\9656.tmp
- %TEMP%\9636.tmp
- %TEMP%\9615.tmp
- %TEMP%\95c6.tmp
- %TEMP%\9587.tmp
- %TEMP%\94ea.tmp
- %TEMP%\943d.tmp
- %TEMP%\941d.tmp
- %TEMP%\9380.tmp
- %TEMP%\9360.tmp
- %TEMP%\9237.tmp
- %TEMP%\9207.tmp
- %TEMP%\91e7.tmp
- %TEMP%\91b7.tmp
- %TEMP%\90bb.tmp
- %TEMP%\9835.tmp
- %TEMP%\9865.tmp
- %TEMP%\90bb.tmp
- %TEMP%\91b7.tmp
- %TEMP%\91e7.tmp
- %TEMP%\9207.tmp
- %TEMP%\9237.tmp
- %TEMP%\9360.tmp
- %TEMP%\9380.tmp
- %TEMP%\941d.tmp
- %TEMP%\943d.tmp
- %TEMP%\94ea.tmp
- %TEMP%\9587.tmp
- 'sg###x62.top':80
- http://sg###x62.top/gate.php
- DNS ASK sg###x62.top
- DNS ASK by###e08.top
- '%WINDIR%\syswow64\cmd.exe' /c timeout -t 5 && del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c timeout -t 5 && del "<Full path to file>"
- '%WINDIR%\syswow64\timeout.exe' -t 5