Malicious WinSCP installer distributed via Google ad (#malvertising).

Cloaking ad domain: putmastering[.]com

Fake WinSCP site:
winscpn[.]com

C2 callbacks:
104.234.10[.]207:7931/itrdd/kcrs/file1.txt
104.234.10[.]207:7931/itrdd/kcrs/file2.txt

https://www.virustotal.com/gui/file/c118895776e75eaa291d2a5f54f1de4f48756aec28cebaa1bf6fd9beb5d36301/detection

VirusTotal

VirusTotal