Technical Information
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\txdn.dll
- %HOMEPATH%\txdn.dll
- <Current directory>\8fff0000
- <PATH_SAMPLE>.xls
- 'dl###ight.com':80
- 'dl###ight.com':443
- 'ha###mout21.com':80
- http://dl###ight.com/wp-includes/zLuZdtVkoriGTaRE/
- http://ha###mout21.com/jetpack-temp/KjOqTnCwBbVrz8w/
- 'dl###ight.com':443
- DNS ASK dl###ight.com
- DNS ASK ha###mout21.com
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\txdn.dll' (with hidden window)