Техническая информация
- '' (загружен из сети Интернет)
- '%APPDATA%\vbc.exe'
- <SYSTEM32>\werfault.exe
- %APPDATA%\vbc.exe
- %TEMP%\liebert.bmp
- http://sc############htandjusticeorganization.duckdns.org/receipt/invoice_10420.doc
- http://sc############htandjusticeorganization.duckdns.org/scmdoc/win32.exe
- DNS ASK sc############htandjusticeorganization.duckdns.org
- DNS ASK se###.##zbanif1abused.xyz
- DNS ASK dd##.#ivethings.xyz
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding