Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'NyanShell' = '<SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe -executionpolicy bypass -noprofile -windowstyle hidden -noexit -file %TEMP...
- %TEMP%\loader.ps1
- http://10#.#9.91.161/bots/putty.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -noprofile -windowstyle hidden -noexit -file %TEMP%\Loader.ps1