Security researcher Marco Ramilli analyzed a new Coronavirus (COVID-19)-themed attack gathering evidence of the alleged involvement of an APT group. The first stage is a fake PDF file used to run initial infection chain. Stage 1 carved Stage 2 from its body by extracting bytes and decoding them using base64 encoding. Stage 2 is a Microsoft compressed CAB file described in the following table. The following image shows the beautified code section of the analyzed file. The attacker copied certutils from local system, by using (ertu.exe) in order to avoid command line detection from public sandboxes.”]
Source: https://securityaffairs.co/wordpress/99977/apt/apt27-abusing-covid-19.html