Техническая информация
- '%WINDIR%\Temp\k.exe'
- '%WINDIR%\Temp\test.exe'
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 2
- '<SYSTEM32>\attrib.exe' -r -a -s -h <DRIVERS>\etc\hosts
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '<SYSTEM32>\attrib.exe' +r +a +s <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\1.bat
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc\hosts /g everyone:f
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc\hosts /g everyone:r
- <SYSTEM32>\1.bat
- <DRIVERS>\hosts
- %WINDIR%\Temp\k.exe
- %WINDIR%\Temp\test.exe
- %WINDIR%\Temp\test.exe
- <DRIVERS>\hosts
- %TEMP%\~DFDEE9.tmp