Technical Information
- '%WINDIR%\syswow64\mshta.exe' "<Current directory>\wordOnline.hta"
- <Current directory>\wordonline.hta
- 'go####designg.com':80
- http://go####designg.com/bmdff/T/5xBOnOkAQixWY7/JQNizzLtuT6BVV0xRecCKVVHAAR6PkgGrIPN/jib2?us#####################################################################################################...
- DNS ASK go####designg.com
- '%WINDIR%\syswow64\regsvr32.exe' c:\users\public\wordOnline.jpg