Technical Information
- <Current directory>\update.temp
- from <Current directory>\update.temp to <Current directory>\éî¶è80.1.9.exe
- '43.##4.131.186':9008
- 'pv.#ohu.com':80
- '43.##2.191.126':80
- http://pv.#ohu.com/cityjson
- http://43.##2.191.126/%E6%B7%B1%E5%BA%A6.exe
- '43.##4.131.186':9008
- DNS ASK pv.#ohu.com
- '<Current directory>\éî¶è80.1.9.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 -n 5 &del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ping 127.0.0.1 -n 5 &del "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 5