Техническая информация
- %TEMP%\ixp000.tmp\rushercrack.bat
- nul
- %HOMEPATH%\.rusherhack\password
- %HOMEPATH%\.rusherhack\username
- %TEMP%\hsperfdata_user\872
- %TEMP%\tmp.vbs
- '<SYSTEM32>\wscript.exe' %TEMP%\tmp.vbs
- '<SYSTEM32>\cmd.exe' /c "rushercrack.bat"
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\config\system"
- '<SYSTEM32>\findstr.exe' /c:"38.##2.201.240 newauth.rusherhack.net" <DRIVERS>\etc\hosts
- '<SYSTEM32>\ipconfig.exe' /flushdns