Technical Information
- <SYSTEM32>\winver.exe
- from <Full path to file> to \:wtfbbq
- 'hk##########z.oss-cn-hongkong.aliyuncs.com':443
- '54.#6.93.43':6605
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?12##############
- 'hk##########z.oss-cn-hongkong.aliyuncs.com':443
- '54.#6.93.43':6605
- DNS ASK hk##########z.oss-cn-hongkong.aliyuncs.com
- '<SYSTEM32>\winver.exe'
- '<SYSTEM32>\winver.exe' ' (with hidden window)