Technical Information
- '<SYSTEM32>\coffire.exe'
- '<SYSTEM32>\rundll64.exe'
- '<SYSTEM32>\spools.exe'
- '<SYSTEM32>\rundll64.exe' (downloaded from the Internet)
- '<SYSTEM32>\spools.exe' (downloaded from the Internet)
- '<SYSTEM32>\coffire.exe' (downloaded from the Internet)
- <SYSTEM32>\rundll64.exe
- <SYSTEM32>\coffire.exe
- <SYSTEM32>\spools.exe
- 'www.c-######eonline.pochta.ru':80
- 'localhost':1038
- http://www.c-######eonline.pochta.ru/rundll64.jpg
- http://www.c-######eonline.pochta.ru/coffire.jpg
- http://www.c-######eonline.pochta.ru/spools.jpg
- DNS ASK www.c-######eonline.pochta.ru