Technical Information
- '<SYSTEM32>\regsvr32.exe' /s calc
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Dis.ooccxx
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disa.ooccxx
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disb.ooccxx
- %TEMP%\mz_etilqs_ssebgq2rpfehzaw
- %TEMP%\mz_etilqs_ivufszdrcge35nz
- %TEMP%\error018880_01.xml
- %TEMP%\mz_etilqs_ggeehk80srwvztv
- %TEMP%\mz_etilqs_e7aw1cwepupo4m1
- %TEMP%\mz_etilqs_s5rwf6d5mqa6wjc
- '14#.#0.87.163':80
- '34.##9.100.209':443
- 'fe########alog-cdn.prod.mozaws.net':443
- '5.###.118.198':80
- '91.##4.11.15':80
- http://91.##4.11.15/44666,6175321759.dat
- '34.##9.100.209':443
- DNS ASK fe########alog-cdn.prod.mozaws.net
- '<SYSTEM32>\regsvr32.exe' /s calc' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Dis.ooccxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disa.ooccxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' %ALLUSERSPROFILE%\Disb.ooccxx' (with hidden window)