Техническая информация
- '%APPDATA%\microsoft\word\winword.exe' https://dl.dropboxusercontent.com/s/7ykh2362es2075y/1.xml https://dl.dropboxusercontent.com/s/9rfalztty6h2n3m/2.xsl
- %TEMP%\hdnei.zip
- %TEMP%\hdnep.zip
- %TEMP%\hdneq.zip
- %APPDATA%\microsoft\word\winword.exe
- %HOMEPATH%\templates\spoolsv.exe
- %HOMEPATH%\templates\mpsvc.dll
- %TEMP%\hdnep.zip
- %TEMP%\hdnei.zip
- %TEMP%\hdneq.zip
- 'dl.#####oxusercontent.com':443
- 'dl.#####oxusercontent.com':443
- DNS ASK dl.#####oxusercontent.com
- '%APPDATA%\microsoft\word\winword.exe' https://dl.dropboxusercontent.com/s/7ykh2362es2075y/1.xml https://dl.dropboxusercontent.com/s/9rfalztty6h2n3m/2.xsl' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding