Technical Information
- ClassName: 'Regmonclass', WindowName: ''
- ClassName: 'Filemonclass', WindowName: ''
- <Current directory>\skinh_el.dll
- <Current directory>\skinh_el.dll
- from <DRIVERS>\etc\hosts to %TEMP%\467363\....\temporaryfile
- 'r.###ne.qq.com':80
- 'r.###ne.qq.com':443
- 'cr#.##gicert-cn.com':80
- 'oc##.dcocsp.cn':80
- 'microsoft.com':80
- 'oc##.#tartssl.com':80
- http://oc##.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHv1Dj%2BciPJEWH5JNtwL5Y07mRqwQUxBF%2BiECGwkG%2FZfMa4bRTQKOr7H0CEArIzKqFYmE3jrS4gQrE3QI%3D
- DNS ASK r.###ne.qq.com
- DNS ASK oc##.dcocsp.cn
- DNS ASK cr#.##gicert-cn.com
- DNS ASK microsoft.com
- DNS ASK st####.rapidssl.com
- DNS ASK oc##.#tartssl.com
- ClassName: '4823-00000029' WindowName: ''
- ClassName: '18467-41' WindowName: ''