Техническая информация
- '%APPDATA%\cnn.exe'
- %APPDATA%\cnn.exe
- 'ql#.ai':80
- '23.#5.60.74':80
- http://ql#.ai/zvE2N
- http://23.#5.60.74/ilovemywifemorethananyoneitsnevernobodyknowbecauseiloveheralotsheismyheart____ilovemywifemorethananyonethankyousoomuch.doc
- http://23.#5.60.74/Clwusaqjs.exe
- DNS ASK ql#.ai
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding