Technical Information
- %TEMP%\test.dll
- %TEMP%\delself.bat
- http://www.55###8.online/black.php?pa#########
- DNS ASK 55###8.online
- ClassName: 'ConsoleWindowClass' WindowName: ''
- '%WINDIR%\syswow64\regsvr32.exe' /s %TEMP%\test.dll' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\delself.bat' (with hidden window)
- '%WINDIR%\syswow64\regsvr32.exe' /s %TEMP%\test.dll
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\delself.bat