Техническая информация
- %TEMP%\wez.cab
- %TEMP%\<Имя файла>.rtf
- '10#.#6.68.55':80
- http://12#.##.0.39:9131/tor/status-vote/current/consensus via 12#.31.0.39
- http://16#.##2.42.4:9030/tor/server/fp/b6320e44a230302c7bf9319e67597a9b87882241 via 16#.#72.42.4
- http://19#.#49.230.105/tor/server/fp/8b8ce56754e0d70b07b59350a41ffcc9381cae88
- http://90.##7.52.233/tor/server/fp/70f9178f819874ae89384de4e09d4c263bee5feb
- http://24.##.67.120:9030/tor/server/fp/70f9178f819874ae89384de4e09d4c263bee5feb via 24.##.67.120
- http://13#.#17.148.45/tor/server/fp/0677df0b05ecda2ef45f26c3332731043bb89ab8
- http://18#.#40.210.20/tor/server/fp/2e6ee0d63eeaa9ff044aa92f951e5767106ff738
- http://78.##.217.214/tor/server/fp/bbc32a8ab917cf01d69e60312b341594d4bf7ab7
- http://69.###.70.73:9030/tor/server/fp/e9b0f7abfb64c6e100b52d8cf2d6b833beb4ff44 via 69.##5.70.73
- http://17#.##4.131.38:9030/tor/server/fp/e9b3a2f0da44aeec2311273909c2627aff783c5b via 17#.#04.131.38
- http://19#.#8.11.219/tor/server/fp/e9c71a8f01eba4a0ad66a8b928775cfeafdf9d3d
- http://37.###.188.140:8080/tor/server/fp/861bcfdd148973985e7fe97c7455c9e4ac4e13be via 37.##2.188.140
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\<Имя файла>.rtf"' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\<Имя файла>.rtf"