Technical Information
- %WINDIR%\syswow64\rundll32.exe
- %TEMP%\~759860.tmp
- %TEMP%\bm22eb.tmp
- %TEMP%\~759860.tmp
- 'jp##.co.kr':80
- 'jp##.co.kr':443
- 'x1.#.lencr.org':80
- http://jp##.co.kr/report_N_0053_7CC7B0FD3104CA01-B9D823ED94D3D801-E616FE0493D3D801-66BC42A092D3D801_66786277706E_75736572_8427BF1B_760626BF_0_started_ext_ALRRR_N_OSBBB_64_OSNNN_Windows_7_Enterp...
- http://jp##.co.kr/report_N_0053_7CC7B0FD3104CA01-B9D823ED94D3D801-E616FE0493D3D801-66BC42A092D3D801_66786277706E_75736572_8427BF1B_760626BF_1_step_0
- http://x1.#.lencr.org/
- http://jp##.co.kr/report_N_0053_7CC7B0FD3104CA01-B9D823ED94D3D801-E616FE0493D3D801-66BC42A092D3D801_66786277706E_75736572_8427BF1B_760626BF_2_step_1
- http://jp##.co.kr/report_N_0053_7CC7B0FD3104CA01-B9D823ED94D3D801-E616FE0493D3D801-66BC42A092D3D801_66786277706E_75736572_8427BF1B_760626BF_3_already_ok
- http://jp##.co.kr/report_N_0053_7CC7B0FD3104CA01-B9D823ED94D3D801-E616FE0493D3D801-66BC42A092D3D801_66786277706E_75736572_8427BF1B_760626BF_4_mark_ok
- http://jp##.co.kr/report_N_0053_7CC7B0FD3104CA01-B9D823ED94D3D801-E616FE0493D3D801-66BC42A092D3D801_66786277706E_75736572_8427BF1B_760626BF_4_watch2_start_575_310
- 'jp##.co.kr':443
- DNS ASK jp##.co.kr
- DNS ASK x1.#.lencr.org
- '%WINDIR%\syswow64\rundll32.exe' shell32.dll,Control_RunDLL