Technical Information
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9R1d5jksc_4jt7v6_1zg.tmp\INV-#00062089367.doc"
- %TEMP%\a9r1d5jksc_4jt7v6_1zg.tmp\inv-#00062089367.doc
- %TEMP%\po.exe
- http://pr###puloss.cz/admin.exe
- DNS ASK pr###puloss.cz
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding