Техническая информация
- '%WINDIR%\syswow64\notepad.exe'
- %TEMP%\48230029.tmp
- %TEMP%\60922355.tmp
- %TEMP%\4954670f.tmp
- %TEMP%\32162ac9.tmp
- %TEMP%\48230029.tmp
- %TEMP%\60922355.tmp
- %TEMP%\4954670f.tmp
- %TEMP%\32162ac9.tmp
- %APPDATA%\Microsoft\Crypto\RSA\S-1-5-21-1960123792-2022915161-3775307078-1001\f58155b4b1d5a524ca0261c3ee99fb50_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- http://bi#.ly/2Np1enh
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK bi#.ly
- DNS ASK do#########ocs.googleusercontent.com
- DNS ASK ap#.#cloud.com
- DNS ASK oc##.#tartssl.com
- '%WINDIR%\syswow64\notepad.exe' ' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /Automation -Embedding