Technical Information
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %TEMP%\asdfgh.lnk
- %TEMP%\vswebview2cache\asdfhcxh.dll
- %TEMP%\asdfgh.lnk
- from %TEMP%\vswebview2cache\asdfhcxh.dll to %TEMP%\modemui.dll
- from %TEMP%\modemui.dll to %TEMP%\tmpbdb3.tmp
- 'fr###l.space':443
- 'fr###l.space':443
- DNS ASK fr###l.space
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %TEMP%\asdfgh.lnk' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "%TEMP%\VSWebView2Cache\asdfhcxh.dll"' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\modemui.dll",CountryRunOnce' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "%TEMP%\VSWebView2Cache\asdfhcxh.dll"
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\modemui.dll",CountryRunOnce