Техническая информация
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9R2itokx_9c32aq_2ag.tmp\invoice-2017.doc"
- '<SYSTEM32>\cmd.exe' /Cstart iexplore https://virustotal.com
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- %TEMP%\a9r2itokx_9c32aq_2ag.tmp\invoice-2017.doc
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies-journal
- %TEMP%\etilqs_uemdgjgtuwm9jjl
- %LOCALAPPDATA%\adobe\acrocef\dc\acrobat\cookie\cookies
- %TEMP%\a9r8linv2_9c32as_2ag.tmp
- 'vi###total.com':443
- 'vi###total.com':443
- DNS ASK vi###total.com
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\cmd.exe' /Cstart iexplore https://virustotal.com' (со скрытым окном)
- '%ProgramFiles(x86)%\internet explorer\iexplore.exe' https://virustotal.com