Техническая информация
- %TEMP%\hosts.cmd
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\hosts.cmd""
- '<SYSTEM32>\cmd.exe' /S /D /c" TYPE "<DRIVERS>\etc\hosts" "
- '<SYSTEM32>\find.exe' /I "genuine.microsoft.com"
- '<SYSTEM32>\find.exe' /I "mpa.one.microsoft.com"
- '<SYSTEM32>\find.exe' /I "sls.microsoft.com"