Technical Information
- '<SYSTEM32>\regsvr32.exe' /s "<Current directory>\141724.tmp"
- <Current directory>\141724.tmp
- from <Current directory>\141724.tmp to <SYSTEM32>\oadoengwepz\ezaeatigkhqxu.dll
- 'al###frique.com':80
- '19#.#99.70.22':8080
- '20#.#8.34.99':8080
- '10#.#1.204.169':8080
- '10#.#24.241.74':8080
- '82.##.180.154':7080
- '18#.#48.169.10':8080
- '37.##.103.148':8080
- '20#.#39.112.82':8080
- '17#.#26.176.79':8080
- '83.##9.80.93':8080
- '17#.#38.33.49':7080
- '18#.#50.48.5':443
- '21#.#8.121.17':443
- '11#.#78.55.22':80
- '93.##.115.205':7080
- '19#.#94.92.175':443
- '13#.#97.14.67':8080
- '62.##1.178.147':8080
- '37.##.244.177':8080
- http://al###frique.com/wp-admin/6zqh/?14########
- '13#.#97.14.67':8080
- '11#.#78.55.22':80
- '21#.#8.121.17':443
- '18#.#50.48.5':443
- '17#.#38.33.49':7080
- '10#.#24.241.74':8080
- '19#.#99.70.22':8080
- DNS ASK al###frique.com
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\OadoEngwEPz\EzaeaTIGKHQxu.dll"