Technical Information
- <SYSTEM32>\setie.bat
- <Current directory>\ipseccmd.dll
- <Current directory>\polstore.dll
- <Current directory>\winipsec.dll
- C:\regset.ini
- '94###jie.com':80
- '94###jie.com':443
- '13######521.474613024.com':8080
- 'qq######iake.blog.163.com':80
- '52###jie.com':80
- '52###jie.com':443
- 'ls##g.com':80
- 'ls##g.com':443
- http://www.94###jie.com/ via 94###jie.com
- http://qq######iake.blog.163.com/blog/static/26430000220167882842196/#
- http://www.52###jie.com/ via 52###jie.com
- http://www.ls##g.com/ via ls##g.com
- DNS ASK www.94###jie.com
- DNS ASK 13######521.474613024.com
- DNS ASK qq######iake.blog.163.com
- DNS ASK www.52###jie.com
- DNS ASK www.ls##g.com
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\setie.bat
- '<SYSTEM32>\regini.exe' c:\regset.ini