Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\gfxv2_0.url
- '' (downloaded from the Internet)
- 'C:\users\public\908.exe'
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9R6qrzyc_1sj23wq_ww.tmp\nnn.doc"
- %TEMP%\a9r6qrzyc_1sj23wq_ww.tmp\nnn.doc
- C:\users\public\908.exe
- %HOMEPATH%\gfxv2_0\gfxv2_0.vbs
- %HOMEPATH%\gfxv2_0\mstsc.exe
- http://bi#.ly/33MD9hU
- http://www.xu##s.com/wp-content/uploads/2019/10/mm.jpg
- DNS ASK bi#.ly
- DNS ASK xu##s.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding