From:
down.malasc.cn/plmm.txt
hxxp://59.34.216.110/m/001.exe
hxxp://59.34.216.110/m/002.exe
hxxp://59.34.216.110/m/003.exe
hxxp://59.34.216.110/m/004.exe
hxxp://59.34.216.110/m/005.exe
hxxp://59.34.216.110/m/006.exe
hxxp://59.34.216.110/m/007.exe
hxxp://59.34.216.110/m/008.exe
hxxp://59.34.216.110/m/009.exe
hxxp://59.34.216.110/m/10.exe
hxxp://59.34.216.110/m/11.exe
hxxp://59.34.216.110/m/12.exe
hxxp://59.34.216.110/m/13.exe
hxxp://59.34.216.110/m/14.exe
hxxp://59.34.216.110/m/15.exe
hxxp://59.34.216.110/m/16.exe
hxxp://59.34.216.110/m/17.exe
hxxp://59.34.216.110/m/18.exe
hxxp://59.34.216.110/m/19.exe
hxxp://59.34.216.110/m/20.exe
hxxp://59.34.216.110/m/21.exe
hxxp://59.34.216.110/m/22.exe
hxxp://59.34.216.110/m/23.exe
hxxp://59.34.216.110/m/24.exe
hxxp://59.34.216.110/m/25.exe
hxxp://59.34.216.110/f.exe
hxxp://59.34.216.110/k.exe
hxxp://59.34.216.110/a.exe
hxxp://59.34.216.110/d.exe
At the time of posting, 10.exe is the only 404:
22e4779acecadb625455d6717e0ed943 *001.exe
089aa8bec1a18ce59349b9dda5dc8f15 *002.exe
5d322179ad31efa1d3af6d5fb35756b3 *003.exe
d2b7be54740f7b73b3dbe40e64c20fde *004.exe
70fb0ab13290bc9e346d80138ff8d835 *005.exe
b1a4501c14e92a0785413328f3b1527a *006.exe
69a08b7e899ec73f18e4bc2d4268c702 *007.exe
7e1670f45f153b646f44a42161e22121 *008.exe
5d93e8dba1c0156ec4e02b6b05670445 *009.exe
1901f88c807e2b659fe181695d4d4993 *11.exe
a9928f12752b6b8bc2b530ad230af79f *12.exe
c29d34638d50a07a96d0372ad39b6277 *13.exe
e4254fdfd40e61b227879417fd4b008e *14.exe
9f7af331b252767f7c1b97f86ff87d32 *15.exe
6a41f55608f635316a4f7bba8c79ace9 *16.exe
cbaadcf72ebb262ab26ee20c09b313c3 *17.exe
27be13591224ea0dcb942519893006e5 *18.exe
7717e996de4d1444c76b3ab4432027b2 *19.exe
e2e6ddd9e493b568f41d782294e30bee *20.exe
d54d42a933f390c30c8d54b5f9df5d4f *21.exe
1620f2e1bebddbcf933aca9a3592b603 *22.exe
5aeef118736c4d564c84d04cc36d05fa *23.exe
62d64ed6124053a257a8d05df435e9be *24.exe
209ed807e3d19e9d6dff57528b6a624d *25.exe
d4e9314d9659b65805cbe96733a253cd *a.exe
520a45d1c99a715095819cef05f170d3 *d.exe
093121189b5f46574d18d56e5f87f8b7 *f.exe
67b85aa272a7b42de634f79d1f2f406b *k.exe
Thanks,
TJS