Technical Information
- '%ProgramFiles%\internet explorer\iexplore.exe' http://kuai.xunlei.com/d/UUHEUNDCCETT
- %TEMP%\bt1700.bat
- %APPDATA%\microsoft\windows\privacie\index.dat
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012023101820231019\index.dat
- %TEMP%\bt1700.bat
- 'ku##.xunlei.com':80
- 'li##.##ve.xunlei.com':80
- 'li##.xunlei.com':443
- 'mi######e-ssl.xunlei.com':443
- 'i.###lei.com':443
- 'mi#####9-ssl.xunlei.com':443
- http://ku##.xunlei.com/d/UUHEUNDCCETT
- http://li##.##ve.xunlei.com/jump?re##############################
- http://li##.xunlei.com/1783948409?re##############################
- 'li##.xunlei.com':443
- 'i.###lei.com':443
- 'mi#####9-ssl.xunlei.com':443
- DNS ASK ku##.xunlei.com
- DNS ASK li##.##ve.xunlei.com
- DNS ASK li##.xunlei.com
- DNS ASK mi######e-ssl.xunlei.com
- DNS ASK i.###lei.com
- DNS ASK mi#####9-ssl.xunlei.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\bt1700.bat "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\bt1700.bat "<Full path to file>"