Technical Information
- <Current directory>\中挖矿病毒被网警通报.docx
- C:\users\public\nid.exe
- nul
- from <Full path to file> to C:\users\public\downloads\telegram.txt
- '12#.#21.120.98':1234
- http://12#.##1.120.98:1234/x86267F8M4pSy4pJojaDAp6jTjUXqZafj7HrMSN7FBR via 12#.#21.120.98
- http://12#.##1.120.98:1234/dpixel via 12#.#21.120.98
- 'C:\users\public\nid.exe'
- '<SYSTEM32>\cmd.exe' " /c " <Current directory>\中挖矿病毒被网警通报.docx' (with hidden window)
- '<SYSTEM32>\cmd.exe' " /c " <Current directory>\中挖矿病毒被网警通报.docx
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "<Current directory>\中挖矿病毒被网警通报.docx"