Technical Information
- %TEMP%\cc14.tmp
- %TEMP%\cca2.tmp
- %TEMP%\cd10.tmp
- %TEMP%\cd7e.tmp
- %TEMP%\cd8f.tmp
- %TEMP%\cdbf.tmp
- %TEMP%\cdcf.tmp
- %TEMP%\cdef.tmp
- %TEMP%\cdf0.tmp
- <Full path to file>{7e15ddeb-8bd6-49f4-a0a4-c65a3e36480c}
- <Current directory>\rcxcf3a.tmp
- %TEMP%\cc14.tmp
- %TEMP%\cca2.tmp
- %TEMP%\cd10.tmp
- %TEMP%\cd7e.tmp
- %TEMP%\cd8f.tmp
- %TEMP%\cdbf.tmp
- %TEMP%\cdcf.tmp
- %TEMP%\cdef.tmp
- %TEMP%\cdf0.tmp
- <Full path to file>{7e15ddeb-8bd6-49f4-a0a4-c65a3e36480c}
- from <Current directory>\rcxcf3a.tmp to <Full path to file>{7e15ddeb-8bd6-49f4-a0a4-c65a3e36480c}
- <Full path to file>
- from <Full path to file> to %TEMP%\_@ce8d.tmp
- 'cf#####i.blog.163.com':80
- http://cf#####i.blog.163.com/blog/static/21795512620156505533625/
- http://bl##.163.com/login.do?er#####
- DNS ASK cf#####i.blog.163.com
- DNS ASK bl##.163.com