Technical Information
- <SYSTEM32>\dllhost.exe
- %APPDATA%\seat\metal\effect.exe
- %APPDATA%\seat\metal\profess.bin
- '19#.#48.57.16':80
- http://19#.#48.57.16/1109860002d645548e1b.php
- '%APPDATA%\seat\metal\effect.exe' "%APPDATA%\Seat\Metal\profess.bin"
- '<SYSTEM32>\dllhost.exe'
- '%APPDATA%\seat\metal\effect.exe' "%APPDATA%\Seat\Metal\profess.bin"' (with hidden window)
- '<SYSTEM32>\dllhost.exe' ' (with hidden window)