Technical Information
- '<SYSTEM32>\regsvr32.exe' /S ..\hhdt1.ocx
- 'we###ulta.com':443
- 'x1.#.lencr.org':80
- 'ch####assion.com':80
- http://x1.#.lencr.org/
- http://ch####assion.com/wp-content/Qcl3YY1jmc/
- 'we###ulta.com':443
- DNS ASK we###ulta.com
- DNS ASK x1.#.lencr.org
- DNS ASK ch####assion.com
- '<SYSTEM32>\regsvr32.exe' /S ..\hhdt1.ocx' (with hidden window)