Technical Information
- '<SYSTEM32>\regsvr32.exe' /s calc
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Dis.ooccxx
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disa.ooccxx
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disb.ooccxx
- %TEMP%\error028320_01.xml
- '14#.#0.87.163':80
- '5.###.118.198':80
- '91.##4.11.15':80
- http://91.##4.11.15/44666,6175321759.dat
- '34.##7.121.53':443
- '<SYSTEM32>\regsvr32.exe' /s calc' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Dis.ooccxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disa.ooccxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disb.ooccxx' (with hidden window)