Technical Information
- '10#.#83.114.5':80
- 'to#s.is':80
- 'to#s.is':443
- http://10#.#83.114.5/1800/HTM/IEhtmlBrowserHistoryRecoveryCleaner.dOC
- http://to#s.is/114*74v6
- 'to#s.is':443
- DNS ASK to#s.is
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding