Technical Information
- 'bi#o.cn':80
- http://www.bi#o.cn/Union/zz.htm
- http://www.bi#o.cn/union/softfy.asp?ne##################################
- http://www.bi#o.cn/ie/union/softfy.asp?ne##################################
- DNS ASK bi#o.cn
- '%WINDIR%\syswow64\cmd.exe' /c rmdir /s/q "%TEMP%\smd#\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c rmdir /s/q "%TEMP%\$2312\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c rmdir /s/q "%TEMP%\smd#\
- '%WINDIR%\syswow64\cmd.exe' /c rmdir /s/q "%TEMP%\$2312\