Technical Information
- <SYSTEM32>\tasks\windows put
- %TEMP%\content\356-4684-<File name>.exe-18-37-27-993.dump
- %APPDATA%\windowsput\winput.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %TEMP%\content\2080-1884-winput.exe-18-37-29-956.dump
- '16#.#.254.101':7070
- 'mo#####.map.fastly.net':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%APPDATA%\windowsput\winput.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "Windows Put" /sc ONLOGON /tr "%APPDATA%\windowsput\WinPut.exe" /rl HIGHEST /f