Technical Information
- '<SYSTEM32>\regsvr32.exe' /S ..\haics1.ocx
- '<SYSTEM32>\regsvr32.exe' /S ..\haics2.ocx
- '<SYSTEM32>\regsvr32.exe' /S ..\haics3.ocx
- <Current directory>\744f0000
- <PATH_SAMPLE>.xls
- 'ch###master.com':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- 'be####endeghaz.hu':443
- 'vi####pparels.com':80
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMtOGB7mVjV%2FZgbCRyKNsOnkA%3D%3D
- http://vi####pparels.com/dQa/Qzuqq5TZO/
- 'ch###master.com':443
- 'be####endeghaz.hu':443
- DNS ASK ch###master.com
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- DNS ASK be####endeghaz.hu
- DNS ASK vi####pparels.com
- DNS ASK st####.rapidssl.com
- '<SYSTEM32>\regsvr32.exe' /S ..\haics1.ocx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\haics2.ocx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\haics3.ocx' (with hidden window)