Техническая информация
- %WINDIR%\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
- 'gg.gg':80
- 'sn############naldodelimeabrazilplayers.duckdns.org':80
- http://gg.gg/Chinese_Private
- http://sn############naldodelimeabrazilplayers.duckdns.org/receipt/invoice_112216.doc
- DNS ASK gg.gg
- DNS ASK sn############naldodelimeabrazilplayers.duckdns.org
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding