Technical Information
- <SYSTEM32>\resato.exe
- <SYSTEM32>\resato.exe
- 'lo######t.ptlogin2.qq.com':4300
- 'qq###.#z01.bdysite.com':80
- http://qq###.#z01.bdysite.com/cc.txt
- DNS ASK lo######t.ptlogin2.qq.com
- DNS ASK qq###.#z01.bdysite.com
- '<SYSTEM32>\resato.exe'