Technical Information
- %WINDIR%\client41913.exe
- %WINDIR%\obcwajm.dll
- %WINDIR%\cle.bat
- 'ud#.#xwan.com':80
- 'cf#.##pinwan.com':80
- 'bk.##7wan.com':80
- http://cf#.##pinwan.com/index/getcfg?id######
- DNS ASK ud#.#xwan.com
- DNS ASK cf#.##pinwan.com
- DNS ASK bk.##7wan.com
- '%WINDIR%\client41913.exe'
- '%WINDIR%\syswow64\cmd.exe' /c call %WINDIR%\cle.bat
- '%WINDIR%\syswow64\ping.exe' 127.0.0.1 -n 3
- '%WINDIR%\client41913.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c call %WINDIR%\cle.bat' (with hidden window)