Technical Information
- '<SYSTEM32>\regsvr32.exe' /S ..\elv1.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv2.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv3.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv4.ooocccxxx
- %HOMEPATH%\elv2.ooocccxxx
- <Current directory>\1b201000
- <PATH_SAMPLE>.xls
- 'vi##z.com':80
- 'yu#####o.raluking.com':80
- 'ak##web.net':443
- 'bd#g.es':80
- http://www.vi##z.com/cache/rqWV/
- http://yu#####o.raluking.com/1eq5o7/gHrTM8YilZz0quKt/
- http://yu#####o.raluking.com/manager
- http://yu#####o.raluking.com/wp-login.php
- http://www.bd#g.es/css/DDm7o71vWtTs/
- DNS ASK vi##z.com
- DNS ASK yu#####o.raluking.com
- DNS ASK ak##web.net
- DNS ASK bd#g.es
- '<SYSTEM32>\regsvr32.exe' /S ..\elv1.ooocccxxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv2.ooocccxxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv3.ooocccxxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv4.ooocccxxx' (with hidden window)