Technical Information
- 'C:\skyse_ch.exe'
- 'C:\skyse_ch.exe' (downloaded from the Internet)
- '<SYSTEM32>\wscript.exe' "%TEMP%\1.tmp\hao.vbs"
- '<SYSTEM32>\ping.exe' -n 1 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\a.bat" "
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\skyse_ch[1].exe
- C:\skyse_ch.exe
- %TEMP%\1.tmp\a.bat
- %TEMP%\1.tmp\hao.vbs
- %TEMP%\1.tmp\a.bat
- %TEMP%\1.tmp\hao.vbs
- 'ad####.hei38.com':80
- 'te##.#inghe.gov.cn':8080
- 'localhost':1036
- ad####.hei38.com/down/32664/skyse_ch.exe
- DNS ASK ad####.hei38.com
- DNS ASK te##.#inghe.gov.cn