Technical Information
- <SYSTEM32>\dllhost.exe
- %ALLUSERSPROFILE%\ntos
- %ALLUSERSPROFILE%\cdat.bin2940
- 'dn#.google':443
- 'la###ugs.hair':80
- 'google.com':80
- 'localhost':49700
- 'la###ugs.hair':443
- 'localhost':49706
- 'localhost':49710
- 'ch#####.amazonaws.com':80
- 'localhost':49716
- 'localhost':49722
- 'localhost':49726
- 'localhost':49730
- 'localhost':49734
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ff##############
- http://la###ugs.hair/Stb/PokerFace/init.php?id###############
- 'dn#.google':443
- 'localhost':49700
- 'localhost':49701
- 'la###ugs.hair':443
- 'localhost':49706
- 'localhost':49707
- 'localhost':49710
- 'localhost':49711
- 'localhost':49716
- 'localhost':49717
- 'localhost':49722
- 'localhost':49723
- 'localhost':49726
- 'localhost':49727
- 'localhost':49730
- 'localhost':49731
- 'localhost':49734
- 'localhost':49735
- DNS ASK dn#.google
- DNS ASK google.com
- DNS ASK la###ugs.hair
- DNS ASK ch#####.amazonaws.com
- '<SYSTEM32>\dllhost.exe'
- '<SYSTEM32>\cmd.exe' dir /a /s /b A:\*imgui_impl_win32.cpp A:\*.suo A:\*.exe A:\*.vcxproj > %ALLUSERSPROFILE%\ADat.bin2940
- '<SYSTEM32>\cmd.exe' dir /a /s /b C:\*imgui_impl_win32.cpp C:\*.suo C:\*.exe C:\*.vcxproj > %ALLUSERSPROFILE%\CDat.bin2940