Technical Information
- %WINDIR%\syswow64\svchost.exe
- 'in###ium.ooo':80
- '91.##1.246.243':80
- http://in###ium.ooo/checks/hndl.txt
- DNS ASK in###ium.ooo
- ClassName: 'ProcessHacker' WindowName: ''
- ClassName: '' WindowName: 'ProcessDumper'
- ClassName: 'RegistryChangesView' WindowName: ''
- ClassName: 'DriverView00' WindowName: ''
- ClassName: 'TStdHttpAnalyzerForm' WindowName: ''
- '%WINDIR%\syswow64\svchost.exe' 2252