Technical Information
- %APPDATA%\microsoft\windows\templates\boost_thread2.dll
- %HOMEPATH%\application data\microsoft\forms\excel.box
- %TEMP%\vbd77.tmp
- %TEMP%\vbe26.tmp
- %TEMP%\vbe48.tmp
- %TEMP%\vbe5b.tmp
- %TEMP%\4f0f0000
- %TEMP%\doreal.xlsx.zip
- %TEMP%\oleobject1.bin
- %APPDATA%\microsoft\windows\templates\boost_thread2.dll
- %TEMP%\vbd76.tmp
- %TEMP%\vbe25.tmp
- %TEMP%\vbe47.tmp
- %TEMP%\vbe5a.tmp
- from %TEMP%\vbd77.tmp to %TEMP%\vbd76.tmp
- from %TEMP%\vbe26.tmp to %TEMP%\vbe25.tmp
- from %TEMP%\vbe48.tmp to %TEMP%\vbe47.tmp
- from %TEMP%\vbe5b.tmp to %TEMP%\vbe5a.tmp
- from %TEMP%\4f0f0000 to %TEMP%\doreal.xlsx
- 'ne###corp.com':443
- DNS ASK ne###corp.com