Техническая информация
- %TEMP%\autab1d.tmp
- %TEMP%\slyzz_spoofer_loader.exe
- %TEMP%\autb117.tmp
- %TEMP%\checklmao.bat
- %TEMP%\autab1d.tmp
- %TEMP%\autb117.tmp
- %TEMP%\slyzz_spoofer_loader.exe
- %TEMP%\checklmao.bat
- '%TEMP%\slyzz_spoofer_loader.exe'
- '%WINDIR%\syswow64\cmd.exe' /c @echo off & echo Running checklmao.bat silently... & start "" /min /b cmd /c "%TEMP%\checklmao.bat & exit"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c @echo off & echo Running checklmao.bat silently... & start "" /min /b cmd /c "%TEMP%\checklmao.bat & exit"
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\checklmao.bat & exit"
- '%WINDIR%\syswow64\findstr.exe' /C:"188.227.86.96 auth.ampled.cc" "<DRIVERS>\etc\hosts"
- '%WINDIR%\syswow64\ipconfig.exe' /flushdns