Technical Information
- %TEMP%\<File name>
- %TEMP%\dydhshsoe.dll
- %TEMP%\seeesisuoeiaqit.tmp
- %TEMP%\javadeployreg.log
- %TEMP%\dd_vcredist_amd64_20151216210341.log
- %TEMP%\adobesfx.log
- %TEMP%\microsoft .net framework 4.7.1 setup_20200610_200621826.html
- %TEMP%\aspnetsetup.log
- %TEMP%\dd_wcf_ca_smci_20200611_031056_919.txt
- %TEMP%\dd_vcredist_amd64_20151216210341_000_vcruntimeminimum_x64.log
- %TEMP%\dotnetfx.log
- %TEMP%\dd_wcf_ca_smci_20200611_031101_060.txt
- %TEMP%\msid38c.log
- %TEMP%\aspnetsetup_00001.log
- %TEMP%\aspnetsetup_00002.log
- %TEMP%\dd_vcredist_x86_20151216210157_000_vcruntimeminimum_x86.log
- %TEMP%\jusched.log
- %TEMP%\dd_vcredist_amd64_20151216210341_001_vcruntimeadditional_x64.log
- %TEMP%\msieb217.log
- '17#.#6.120.215':443
- '10#.#87.26.147':443
- '17#.#6.120.138':443
- 'microsoft.com':80
- '21#.#27.155.103':443
- 'localhost':14643
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- '10#.#87.26.147':443
- '17#.#6.120.138':443
- '21#.#27.155.103':443
- DNS ASK microsoft.com
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\Dydhshsoe.dll,start' (with hidden window)
- '<SYSTEM32>\rundll32.exe' "<SYSTEM32>\shell32.dll",#61 14643' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\Dydhshsoe.dll,start
- '<SYSTEM32>\rundll32.exe' "<SYSTEM32>\shell32.dll",#61 14643