Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\flowersfollowingflowers.vBS"
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\i3nmat9z\config14[1].txt
- %APPDATA%\flowersfollowingflowers.vbs
- <Текущая директория>\79051000
- <PATH_SAMPLE>.xls
- 'ho#.fyi':80
- '10#.#86.67.211':80
- '91.##.254.29':80
- http://ho#.fyi/lbG0m
- http://10#.#86.67.211/50650/zro/zero.zrzr.zrzr.zrzrzr.doc
- http://10#.#86.67.211/50650/flowersfollowingflowers.gif
- DNS ASK ho#.fyi
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding