Техническая информация
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9Rxp3ojd_1axihzm_vk.tmp\eicar-dropper.doc"
- rdrcef.exe
- [\REGISTRY\USER\S-1-5-21-1238866942-1249195528-555854008-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [\REGISTRY\USER\S-1-5-21-1238866942-1249195528-555854008-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies-journal
- %TEMP%\etilqs_1guulypef4mdbb1
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies
- %TEMP%\a9r1864ghl_1axihzo_vk.tmp
- '34.##0.144.191':443
- '34.##9.100.209':443