Technical Information
- <SYSTEM32>\tasks\putty client
- <SYSTEM32>\tasks\putty ssh client
- %ALLUSERSPROFILE%\puttyclient\puttyclient.exe
- '<SYSTEM32>\cmd.exe' /C "WMIC BIOS GET SERIALNUMBER"
- '<SYSTEM32>\wbem\wmic.exe' BIOS GET SERIALNUMBER
- '<SYSTEM32>\cmd.exe' /C "WMIC DISKDRIVE GET SERIALNUMBER"
- '<SYSTEM32>\wbem\wmic.exe' DISKDRIVE GET SERIALNUMBER
- '<SYSTEM32>\cmd.exe' /C "WMIC CPU GET ProcessorID"
- '<SYSTEM32>\wbem\wmic.exe' CPU GET ProcessorID
- '<SYSTEM32>\cmd.exe' /c "del <Full path to file>"
- '<SYSTEM32>\cmd.exe' /C "WMIC BIOS GET SERIALNUMBER"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "WMIC DISKDRIVE GET SERIALNUMBER"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C "WMIC CPU GET ProcessorID"' (with hidden window)