Technical Information
- '<SYSTEM32>\cmd.exe' /c start "" 18.exe
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2020
- %HOMEPATH%\application data\microsoft\forms\excel.box
- %HOMEPATH%\documents\18.exe
- %TEMP%\1277507.cvr
- '95.##6.189.14':80
- http://95.##6.189.14/w4
- '<SYSTEM32>\cmd.exe' /c start "" 18.exe' (with hidden window)