Technical Information
- <SYSTEM32>\svchost.exe
- %TEMP%\db.dat
- %TEMP%\db.dll
- %TEMP%\db.dat
- 'xv.##zgamen.com':443
- 'xv.##zgamen.com':443
- DNS ASK xv.##zgamen.com
- DNS ASK y1.##bbyykk.com
- DNS ASK
- DNS ASK
- DNS ASK
- DNS ASK
- DNS ASK
- 'y1.##bbyykk.com':53
- '<SYSTEM32>\rundll32.exe' "%TEMP%\db.dll",open
- '<SYSTEM32>\svchost.exe' -k WspService