Technical Information
- '<SYSTEM32>\rundll32.exe' "%APPDATA%\Microsoft\bruhdll32.dll",FckUDud
- %APPDATA%\microsoft\bruhdll32.dll
- %APPDATA%\microsoft\temp.xls
- %TEMP%\excel\temp.xls
- 'pi#####igglystores.shop':443
- 'pi#####igglystores.shop':443
- DNS ASK pi#####igglystores.shop
- ClassName: 'XLMAIN' WindowName: 'Microsoft Excel'
- '%ProgramFiles%\microsoft office\office14\excel.exe' /dde
- '<SYSTEM32>\rundll32.exe' "%APPDATA%\Microsoft\bruhdll32.dll",FckUDud' (with hidden window)