Technical Information
- '<SYSTEM32>\regsvr32.exe' /u /s "%TEMP%\Realtek(r)Audio.dll"
- %TEMP%\realtek(r)audio.dll
- %APPDATA%\microsoft\temp.xlsx
- %APPDATA%\microsoft\~$temp.xlsx
- 'ca####tokens.com':80
- 'ev######ngandthedog.shop':443
- http://ca####tokens.com/static/images/terms/x16jsxq8bfzka32jzsatvd6tv/post.jsp
- 'ev######ngandthedog.shop':443
- DNS ASK ca####tokens.com
- DNS ASK ev######ngandthedog.shop
- ClassName: 'XLMAIN' WindowName: 'Microsoft Excel'
- '%ProgramFiles%\microsoft office\office14\excel.exe' /dde