Technical Information
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv1.ooccxx
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv2.ooccxx
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv3.ooccxx
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv4.ooccxx
- <Current directory>\71f31000
- <PATH_SAMPLE>.xls
- 'ti##s.my':80
- 'mo#####neering.org.tw':80
- 'mo#####neering.org.tw':443
- 'vo###kilina.gr':80
- http://ti##s.my/wp-includes/1OgxQPFaUhS/
- http://www.mo#####neering.org.tw/jp.bad/WWhvAMebz5qT/
- http://vo###kilina.gr/6vtelq/Xo7C7m/
- 'mo#####neering.org.tw':443
- DNS ASK ti##s.my
- DNS ASK mo#####neering.org.tw
- DNS ASK vo###kilina.gr
- DNS ASK ca###rapola.es
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv1.ooccxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv2.ooccxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv3.ooccxx' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /S ..\oxnv4.ooccxx' (with hidden window)