Technical Information
- '<SYSTEM32>\regsvr32.exe' /S ..\haics1.ocx
- '<SYSTEM32>\regsvr32.exe' /S ..\haics2.ocx
- '<SYSTEM32>\regsvr32.exe' /S ..\haics3.ocx
- %HOMEPATH%\haics3.ocx
- <Current directory>\02031000
- <PATH_SAMPLE>.xls
- 'bu#######aquantumhealing.org':443
- 'fa###nfilms.com':443
- 'ro##el.mx':80
- http://ro##el.mx/wp-includes/uX2WDFhrE/
- http://ro##el.mx/cgi-sys/suspendedpage.cgi
- 'bu#######aquantumhealing.org':443
- 'fa###nfilms.com':443
- DNS ASK bu#######aquantumhealing.org
- DNS ASK fa###nfilms.com
- DNS ASK ro##el.mx
- '<SYSTEM32>\regsvr32.exe' /S ..\haics1.ocx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\haics2.ocx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\haics3.ocx' (with hidden window)