Technical Information
- <DRIVERS>\etc\hosts
- '12#.#25.114.144':80
- http://www.ba##u.com/ via 12#.#25.114.144
- DNS ASK www.ba##u.com
- '<SYSTEM32>\cmd.exe' /c echo y|cacls <DRIVERS>\etc\hosts /g everyone:f
- '<SYSTEM32>\cmd.exe' /S /D /c" echo y"
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc\hosts /g everyone:f
- '<SYSTEM32>\cmd.exe' /c attrib -r -a -s -h <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' -r -a -s -h <DRIVERS>\etc\hosts
- '<SYSTEM32>\cmd.exe' /c attrib +r +a +s +h <DRIVERS>\etc\hosts
- '<SYSTEM32>\attrib.exe' +r +a +s +h <DRIVERS>\etc\hosts