Техническая информация
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1336
- %HOMEPATH%\bapo1.xls
- %HOMEPATH%\~$bapo1.xls
- %HOMEPATH%\bapo1.doc
- %HOMEPATH%\~$bapo1.doc
- %HOMEPATH%\bapo1.pub
- %HOMEPATH%\~$bapo1.pub
- %HOMEPATH%\bapo1.dll
- %TEMP%\918097.cvr
- %HOMEPATH%\~$bapo1.xls
- %HOMEPATH%\~$bapo1.doc
- %HOMEPATH%\~$bapo1.pub
- %HOMEPATH%\bapo1.doc в %HOMEPATH%\~wrl2932.tmp
- %HOMEPATH%\bapo1.pub в %HOMEPATH%\~wrl3146.tmp
- %HOMEPATH%\bapo1.doc в %HOMEPATH%\~wrl3353.tmp
- %HOMEPATH%\~$bapo1.doc
- %HOMEPATH%\~$bapo1.pub
- DNS ASK bi####eyboss.xyz
- '<SYSTEM32>\certutil.exe' -decode %HOMEPATH%\Bapo1.xls %HOMEPATH%\Bapo1.dll
- '<SYSTEM32>\rundll32.exe' %HOMEPATH%\Bapo1.dll,Init