Technical Information
- %WINDIR%\ry9dhi3n3.exe
- %TEMP%\content\3984-484-ry9dhi3n3.exe-11-26-20-432.dump
- from %WINDIR%\ry9dhi3n3.exe to %TEMP%\907562\....\temporaryfile
- 'st##mcom.cn':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'st##mcom.cn':443
- DNS ASK st##mcom.cn
- DNS ASK x1.#.lencr.org
- '%WINDIR%\ry9dhi3n3.exe'