Техническая информация
- <SYSTEM32>\tasks\system32
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK drive.google.com
- DNS ASK microsoft.com
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn System32 /tr "%APPDATA%\Honeygain\Honeygain.exe" /sc ONLOGON
- '%WINDIR%\syswow64\schtasks.exe' /create /tn System32 /tr "%APPDATA%\Honeygain\Honeygain.exe" /sc ONLOGON
- '%WINDIR%\syswow64\cmd.exe' /c tar -xvzf%APPDATA%\Honeygain.tar.gz -C%APPDATA%
- '%WINDIR%\syswow64\cmd.exe' /c del /f %APPDATA%\Honeygain.tar.gz