Filename-handling slip let attackers evade FireEye analysis

Does WNT's COPY (or a suitable homegrown substitute) not have some kind of completion status that might perhaps have been checked in the script to make sure that what had happened was what was hoped for?

What kind of organisation lets people write this kind of rubbish?

Yet more proof that WNT wasn't, isn't, and never will be VMS++.

