Technical Information
- '%TEMP%\pusk.exe'
- '%TEMP%\pusk.exe' (downloaded from the Internet)
- '<SYSTEM32>\svchost.exe' <Full path to file>
- <SYSTEM32>\svchost.exe
- %TEMP%\pusk.exe
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\pusk[1].exe
- 'hd##skh.net':80
- http://hd##skh.net/pusk.exe
- DNS ASK hd##skh.net