Technical Information
- '' (downloaded from the Internet)
- '%APPDATA%\conhost.exe'
- %APPDATA%\conhost.exe
- '19#.#.176.142':80
- http://19#.#.176.142/ugcu/Microsoftaianterioerdesigntrackingnewproteocoltoentireprocessupdationcompletewithnewofficeup.doC
- http://19#.#.176.142/9989/conhost.exe
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding