Technical Information
- %WINDIR%\explorer.exe
- iexplore.exe
- iexplore.exe process, wininet.dll module
- http://ri####logistics.com/js/jquery/public/cagefs/files/bin/8900HY.bin
- DNS ASK ri####logistics.com
- '%WINDIR%\syswow64\rundll32.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"