Technical Information
- '<SYSTEM32>\regsvr32.exe' /S ..\elv1.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv2.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv3.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv4.ooocccxxx
- %HOMEPATH%\elv4.ooocccxxx
- <Current directory>\a85f0000
- <PATH_SAMPLE>.xls
- 'fi###tlet.com':80
- 'ce###in.com.ar':80
- 'ca##.co.il':80
- http://fi###tlet.com/logs/OGlRuU/
- http://www.ce###in.com.ar/administrator/viA95RR/
- http://ca##.co.il/_js/dooigYa/
- DNS ASK fi###tlet.com
- DNS ASK ce###in.com.ar
- DNS ASK bl####equila.com.br
- DNS ASK ca##.co.il
- '<SYSTEM32>\regsvr32.exe' /S ..\elv1.ooocccxxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv2.ooocccxxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv3.ooocccxxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv4.ooocccxxx' (with hidden window)