Technical Information
- <Current directory>\v33r.exe
- <Full path to file>
- from <Full path to file> to <Current directory>\v33r.exe
- 'localhost':49694
- 'ke##uth.win':443
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ea##############
- 'localhost':49694
- 'localhost':49695
- 'ke##uth.win':443
- DNS ASK ke##uth.win
- '<SYSTEM32>\cmd.exe' /c cls
- '<SYSTEM32>\cmd.exe' /c certutil -hashfile "<Full path to file>" MD5 | find /i /v "md5" | find /i /v "certutil"
- '<SYSTEM32>\certutil.exe' -hashfile "<Full path to file>" MD5
- '<SYSTEM32>\find.exe' /i /v "md5"
- '<SYSTEM32>\find.exe' /i /v "certutil"