Technical Information
- '<SYSTEM32>\rundll32.exe' ..\zfbfg.ere,DllRegisterServer
- <Current directory>\6ec80000
- <PATH_SAMPLE>.xls
- 'us#####cqme03dymh.xyz':80
- DNS ASK us#####cqme03dymh.xyz
- '<SYSTEM32>\rundll32.exe' ..\zfbfg.ere,DllRegisterServer' (with hidden window)