Техническая информация
- %ProgramFiles(x86)%\steam\steam.exe
- steam.exe
- %TEMP%\tmpinwb-.txt
- %TEMP%\tmpinwb-.txt в %TEMP%\tmpinwb.exe
- %ProgramFiles(x86)%\steam\steam.exe в %ProgramFiles(x86)%\steam\dumper.exe
- %ProgramFiles(x86)%\Steam\Steam.exe
- '5.##.124.175':80
- '%TEMP%\tmpinwb.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cd %temp% & ren tmpinWb-.txt tmpinWb.exe & start /b tmpinWb.exe